The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

The PoeLLM cryptomining campaign has compromised over 3,400 AI servers since April 2026, targeting exposed AI services like LiteLLM, Ollama, and Gotenberg PDF converter. The malware uses an innovative command-and-control mechanism, extracting IPv4 addresses from keywords in a poem hosted on GitHub. Once infected, servers become scanning platforms that exploit CVE-2026-42271 and CVE-2026-48710 for unauthenticated remote code execution while mining cryptocurrency through the Kryptex service. Peak activity reached 800 active infected systems in a single day, primarily affecting systems across the United States and Western Europe. This incident highlights the growing threat to AI infrastructure, as these systems often run on powerful GPU clusters with poor security configurations and excessive internet exposure, making them prime targets for cryptomining operations.

Why This Matters Now

AI infrastructure is rapidly expanding with insufficient security controls, creating lucrative targets for cryptomining attacks. Organizations deploying AI services urgently need robust security frameworks to protect high-value GPU resources from exploitation.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

PoeLLM extracts four words from a poem titled 'On the Nature of Connection' hosted in a GitHub repository, then maps these words to numbers using a hard-coded dictionary to generate IPv4 addresses for C2 servers.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained the PoeLLM cryptomining campaign by limiting attacker reach across cloud-hosted AI infrastructure. Segmentation and east-west traffic controls would likely have reduced the blast radius from 3,400+ compromised servers.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Identity-aware access controls would likely have restricted initial exposure of vulnerable AI services to only authorized clients and workloads

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Workload-level isolation would likely have constrained the malware's ability to escalate beyond the initially compromised AI service boundaries within the host environment

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely have blocked unauthorized scanning activities between compromised AI servers and other workloads across the cloud infrastructure

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Comprehensive traffic visibility would likely have detected the unusual GitHub communication patterns and subsequent connections to dynamically resolved C2 infrastructure

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have blocked unauthorized outbound connections from AI workloads to external cryptocurrency mining services and geographically restricted destinations

Impact (Mitigations)

While cryptomining operations may still have occurred on initially compromised systems, the scope would likely have been constrained to isolated workload boundaries rather than spreading across thousands of AI servers

Impact at a Glance

Affected Business Functions

  • AI/ML Model Serving
  • Cloud Computing Infrastructure
  • Development and DevOps Platforms
  • Document Processing Services
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $250,000

Data Exposure

Potential access to AI model training data, API keys, internal network resources, and compute infrastructure configurations. No confirmed data exfiltration but cryptocurrency mining operations consuming significant computational resources.

Recommended Actions

  • • Implement Zero Trust segmentation to prevent lateral scanning between AI services and restrict east-west traffic flows
  • • Deploy egress security controls with FQDN filtering to block unauthorized communications to cryptomining pools and C2 infrastructure
  • • Enable multicloud visibility to detect anomalous scanning patterns and repeated malformed requests targeting AI service endpoints
  • • Apply inline IPS with updated signatures to identify and block CVE-2026-42271 exploitation attempts against LiteLLM services
  • • Establish cloud firewall policies with AI-driven traffic discovery to identify and control outbound connections from AI workloads

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image