PoeLLM Malware Hijacks 3,400+ Servers for Crypto Mining and Botnet Expansion

A cryptocurrency mining campaign dubbed PoeLLM has compromised more than 3,400 servers by targeting exposed AI infrastructure and other internet-facing applications. Active since April 2026, the operation combines vulnerability exploitation, cryptocurrency miners and an unusual command-and-control mechanism that derives server addresses from a poem hosted on GitHub. Victims predominantly run LiteLLM, Ollama, Gotenberg and Gitea, […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: