Executive Summary
The PoeLLM cryptomining campaign has compromised over 3,400 AI servers since April 2026, targeting exposed AI services like LiteLLM, Ollama, and Gotenberg PDF converter. The malware uses an innovative command-and-control mechanism, extracting IPv4 addresses from keywords in a poem hosted on GitHub. Once infected, servers become scanning platforms that exploit CVE-2026-42271 and CVE-2026-48710 for unauthenticated remote code execution while mining cryptocurrency through the Kryptex service. Peak activity reached 800 active infected systems in a single day, primarily affecting systems across the United States and Western Europe. This incident highlights the growing threat to AI infrastructure, as these systems often run on powerful GPU clusters with poor security configurations and excessive internet exposure, making them prime targets for cryptomining operations.
Why This Matters Now
AI infrastructure is rapidly expanding with insufficient security controls, creating lucrative targets for cryptomining attacks. Organizations deploying AI services urgently need robust security frameworks to protect high-value GPU resources from exploitation.
Attack Path Analysis
PoeLLM attackers exploited exposed AI services (LiteLLM, Ollama) and vulnerable endpoints (CVE-2026-42271) to gain initial access to cloud-hosted AI servers. After compromising systems, they deployed cryptomining malware and established C2 communication through a novel GitHub-hosted poetry mechanism. Compromised servers became scanning platforms to identify additional vulnerable AI services on ports 3000/4000, enabling lateral spread across cloud environments. The malware maintained persistent C2 channels while victims communicated with Russian mining services, effectively monetizing GPU resources for cryptocurrency mining operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited exposed AI services (LiteLLM, Ollama, Gotenberg) and chained CVE-2026-42271 with CVE-2026-48710 for unauthenticated remote code execution on misconfigured cloud-hosted AI servers
Related CVEs
CVE-2026-42271
CVSS 8.8Server-side request forgery (SSRF) vulnerability in LiteLLM's MCP server test endpoints allows authenticated attackers to access internal resources and potentially execute remote code when chained with CVE-2026-48710.
Affected Products:
LiteLLM LiteLLM – < 1.47.4
Exploit Status:
exploited in the wildCVE-2026-48710
CVSS 6.5Authentication bypass vulnerability in LiteLLM that can be chained with CVE-2026-42271 to achieve unauthenticated remote code execution on exposed MCP server endpoints.
Affected Products:
LiteLLM LiteLLM – < 1.47.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter: Unix Shell
Application Layer Protocol: Web Protocols
Remote System Discovery
Network Service Discovery
Lateral Tool Transfer
Resource Hijacking
Web Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST Cybersecurity Framework 2.0 – Vulnerability Management Plan
Control ID: PR.IP-12
PCI DSS 4.0 – Configuration Standards for System Components
Control ID: 2.2.1
CISA Zero Trust Maturity Model 2.0 – Micro-segmentation and Least Privilege Access
Control ID: Networks.B.3
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
DORA – Identification and Classification of ICT Assets
Control ID: Article 8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Exposed AI servers running LiteLLM and Ollama vulnerable to PoeLLM cryptomining malware exploiting CVE-2026-42271 for remote code execution and botnet recruitment.
Computer Software/Engineering
Development environments using Gitea toolkit and AI tools targeted by PoeLLM malware for cryptomining operations, compromising GPU clusters and development infrastructure.
Financial Services
AI-powered financial applications face cryptomining attacks through exposed LiteLLM endpoints, requiring enhanced egress security and zero trust segmentation per compliance frameworks.
Health Care / Life Sciences
Healthcare AI systems vulnerable to PoeLLM malware targeting exposed services, requiring HIPAA-compliant encrypted traffic and enhanced threat detection for patient data protection.
Sources
- PoeLLM malware infects exposed AI servers in cryptomining attackshttps://www.bleepingcomputer.com/news/security/poellm-malware-infects-exposed-ai-servers-in-cryptomining-attacks/Verified
- Canto Incognito: Tracking the PoeLLM Malwarehttps://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malwareVerified
- CVE-2026-42271 Chained with CVE-2026-48710 Researchhttps://horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-chained-with-cve-2026-48710/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained the PoeLLM cryptomining campaign by limiting attacker reach across cloud-hosted AI infrastructure. Segmentation and east-west traffic controls would likely have reduced the blast radius from 3,400+ compromised servers.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access controls would likely have restricted initial exposure of vulnerable AI services to only authorized clients and workloads
Control: Zero Trust Segmentation
Mitigation: Workload-level isolation would likely have constrained the malware's ability to escalate beyond the initially compromised AI service boundaries within the host environment
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely have blocked unauthorized scanning activities between compromised AI servers and other workloads across the cloud infrastructure
Control: Multicloud Visibility & Control
Mitigation: Comprehensive traffic visibility would likely have detected the unusual GitHub communication patterns and subsequent connections to dynamically resolved C2 infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have blocked unauthorized outbound connections from AI workloads to external cryptocurrency mining services and geographically restricted destinations
While cryptomining operations may still have occurred on initially compromised systems, the scope would likely have been constrained to isolated workload boundaries rather than spreading across thousands of AI servers
Impact at a Glance
Affected Business Functions
- AI/ML Model Serving
- Cloud Computing Infrastructure
- Development and DevOps Platforms
- Document Processing Services
Estimated downtime: 7 days
Estimated loss: $250,000
Potential access to AI model training data, API keys, internal network resources, and compute infrastructure configurations. No confirmed data exfiltration but cryptocurrency mining operations consuming significant computational resources.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to prevent lateral scanning between AI services and restrict east-west traffic flows
- • Deploy egress security controls with FQDN filtering to block unauthorized communications to cryptomining pools and C2 infrastructure
- • Enable multicloud visibility to detect anomalous scanning patterns and repeated malformed requests targeting AI service endpoints
- • Apply inline IPS with updated signatures to identify and block CVE-2026-42271 exploitation attempts against LiteLLM services
- • Establish cloud firewall policies with AI-driven traffic discovery to identify and control outbound connections from AI workloads



