PoeLLM Malware: The Poet Laureate of Cybercrime

By Bill Toulas
October 7, 2026

So, you thought your AI servers were safe? Think again! A new malware, cleverly named PoeLLM, has decided to turn exposed AI services into its own personal playground for cryptomining. Because, why not blend bad poetry with cybercrime?

What's Happening?

PoeLLM is like that overly ambitious student who scans the room looking for weak spots—except instead of a classroom, it targets over 3,400 poorly secured servers. Oh yes, we're talking peak activity levels of 800 infected systems per day. If only we could harness that energy for something productive… like writing more poetry.

The Unique Approach

This malware has an unusual twist: It retrieves its control commands from a poem titled “On the Nature of Connection.” Apparently, the author thought, “Hey, what if I combined my passion for poetry with malware? That’ll confuse the cyber cops!” The malware extracts four phrases from this poem (thankfully, we don't have to read it ourselves) to generate an IP address. 11 revisions and counting—clearly, the hacker is striving for literary greatness while they’re at it.

The Target List

PoeLLM isn't picky—it's hitting systems running a variety of AI tools like LiteLLM and Ollama, plus Gotenberg PDF converters. If it’s weakly configured and exposed online, it’s fair game. The beauty of it? These systems often run on powerful GPUs, which are just perfect for cryptomining.

Attack Mechanics

Once it finds a suitable server to invade, this malware acts like a sticky burr. It grabs hold, spreads itself, and starts scanning for other vulnerable ports. To make matters worse, it has a fondness for a vulnerability in LiteLLM that was once thought to require authentication. Surprise! It does not.

Who’s Behind This?

While the researchers don't have a smoking gun, they suspect the genius behind PoeLLM might be Italian based on some comments in the malware and a server located in Italy. Guess the Mediterranean diet doesn’t only apply to pasta!

What Can You Do?

If you’re an admin and you've accidentally left the front door open, it's time to take action. Make sure you apply security updates, limit your server’s exposure to the internet, and keep a close eye on your network logs. Unless, of course, you enjoy chaos and cybercriminals having a field day with your resources.

Important Update

Oh, and by the way, the number of compromised servers was updated from 2,100 to a whopping 3,400. Because who doesn’t love a good plot twist?

So, as we go about our day, remember: If you thought poetry was just for English classes, think again. It’s now a tool for hackers. Who knew literary studies could be this dangerous?

Read More

Got Something To Say?

Your email address will not be published.