Full Report
A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. [...]
Analysis Summary
# Tool/Technique: PoeLLM
## Overview
PoeLLM is a sophisticated ELF-based malware botnet that targets exposed AI services and development tools. Its primary purpose is to hijack high-performance hardware (specifically GPU clusters used for LLMs) for cryptocurrency mining and to use compromised servers as launchpads for further network scanning and exploit deployment. It is notable for its creative C2 retrieval mechanism involving steganographic-like word mapping from poetry hosted on GitHub.
## Technical Details
- **Type**: Malware family (Botnet / Loader / Miner)
- **Platform**: Linux (ELF files)
- **Capabilities**: Remote shell, C2 domain generation, network scanning, exploit deployment, and cryptomining.
- **First Seen**: April 2026
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1190 - Exploit Public-Facing Application] (Targeting CVE-2026-42271 in LiteLLM)
- **[TA0011 - Command and Control]**
- [T1102.001 - Web Service: Dead Drop Resolver] (Retrieving C2 from GitHub-hosted CSS/Poem)
- [T1568.002 - Domain Generation Algorithms] (Custom word-to-IP mapping)
- **[TA0007 - Discovery]**
- [T1046 - Network Service Scanning] (Scanning ports 3000 and 4000)
- **[TA0040 - Resource Hijacking]**
- [T1496 - Resource Hijacking] (Cryptomining via XMRig and Iron)
## Functionality
### Core Capabilities
- **C2 Retrieval**: The malware downloads a file named `dash.css` from a GitHub repository. It extracts four specific keywords from a poem titled “On the Nature of Connection.” These words are cross-referenced against a hard-coded internal dictionary to generate a four-octet IPv4 address.
- **Cryptomining**: Deploys XMRig and Iron miners, specifically targeting the high-performance GPU/CPU resources of AI servers.
- **Propagation/Lateral Movement**: Scans the network for ports 3000 (Gotenberg) and 4000 (LiteLLM) to identify new targets.
### Advanced Features
- **Exploit Chaining**: Capable of deploying exploits for CVE-2026-42271. When combined with CVE-2026-48710, it achieves unauthenticated Remote Code Execution (RCE) on LiteLLM MCP server endpoints.
- **Stealth Infrastructure**: Uses compromised routers as C2 nodes to mask the attacker's true origin.
- **Persistence/Remote Access**: Includes a remote shell functionality for direct manual control by the operator.
## Indicators of Compromise
- **File Hashes**:
- (SHA256): [Not explicitly listed in the article snippet, typically associated with `libgcrypt` ELF file]
- **File Names**:
- `libgcrypt` (Malicious ELF)
- `dash.css` (C2 configuration file)
- **Network Indicators**:
- `github[.]com` (Specifically a repository forking Node.js)
- Port 3000 (Gotenberg)
- Port 4000 (LiteLLM)
- Connection to Russian mining service: `kryptex[.]com`
- **Behavioral Indicators**:
- Unexpected outbound traffic on ports associated with Monero or Iron mining.
- Presence of ELF files named after standard libraries (`libgcrypt`) in non-standard directories or with unusual checksums.
## Associated Threat Actors
- **Attribution**: No named group; however, researchers assess with moderate confidence that the operator is **Italian-based**, due to code comments and server locations.
## Detection Methods
- **Signature-based**: Monitor for the specific ELF file `libgcrypt` and the C2-mapping dictionary within binaries.
- **Behavioral**: Flag systems scanning internal or external networks on ports 3000 and 4000. Monitor for unauthorized access to LiteLLM endpoints.
- **Network**: Monitor for egress traffic to GitHub specifically requesting the `dash.css` file from unauthorized repositories.
## Mitigation Strategies
- **Patch Management**: Immediately patch LiteLLM, Gotenberg, and Ollama services. Specifically, address CVE-2026-42271 and CVE-2026-48710.
- **Network Hardening**: Restrict access to AI management interfaces (LiteLLM, Ollama) to trusted IPs only; do not expose them to the public internet.
- **Ingress/Egress Filtering**: Block outbound connections to known mining pools (e.g., Kryptex) from production AI clusters.
## Related Tools/Techniques
- **XMRig**: Open-source miner frequently bundled in botnets.
- **Dead Drop Resolvers**: A technique commonly used by advanced actors to hide C2 infrastructure behind legitimate services like GitHub, Pastebin, or social media.