PoeLLM malware targets exposed AI servers in cryptomining attacks
A cryptomining campaign is targeting exposed AI services with PoeLLM malware to compromise servers.

Cybersecurity researchers have uncovered a new cryptomining campaign that specifically targets exposed and unprotected artificial intelligence servers using PoeLLM malware.
The malicious software infiltrates vulnerable AI services, taking over compromised servers and turning them into covert cryptomining nodes.
In addition to mining cryptocurrency, the infected servers are repurposed as network scanners and launchpads to exploit other targets across the web.
This campaign serves as a critical reminder for IT administrators and tech professionals globally regarding the necessity of securing server infrastructure.
Failing to implement proper security controls when deploying AI services can expose organizations to severe operational and security risks.
Experts advise immediate security audits of all publicly accessible AI endpoints to prevent unauthorized access and potential compromise.



