$ techbeacon▋
CVE & Exploits

Cybercriminals Deploy PoeLLM Malware to Hijack Unsecured AI Platforms for Crypto Mining

Cybercriminals Deploy PoeLLM Malware to Hijack Unsecured AI Platforms for Crypto Mining

Security researchers have uncovered a new wave of cryptomining activity that exploits publicly accessible artificial‑intelligence servers, using a malicious tool dubbed PoeLLM to transform compromised machines into both scanning bots and launchpads for further attacks.

The campaign targets AI services that lack proper authentication or network restrictions, allowing threat actors to gain remote code execution. Once inside, the PoeLLM payload installs a lightweight miner that taps the server's processing power to generate cryptocurrency, while simultaneously configuring the host to probe other vulnerable AI endpoints.

According to analysis shared by BleepingComputer, the malware is designed to be modular. Its initial component establishes persistence and harvests system information, after which a secondary module downloads additional exploit code. This architecture enables the infected server to act as a proxy, relaying traffic to other compromised AI instances and amplifying the scale of the cryptomining operation.

The rise of exposed AI APIs has created an attractive attack surface. Many providers expose models for public testing or integration without enforcing strict access controls, leaving them vulnerable to automated scans. By co‑opting these high‑performance compute resources, attackers can achieve mining rates far beyond what typical botnets provide, making the illicit activity more profitable.

Experts warn that the threat extends beyond financial theft. The scanning capability embedded in PoeLLM allows adversaries to map networks of AI services, potentially identifying further weaknesses for data exfiltration, ransomware deployment, or the distribution of additional malware families.

Mitigation efforts focus on tightening API authentication, implementing network segmentation, and monitoring for anomalous CPU usage patterns indicative of mining. Organizations running AI workloads are advised to audit exposed endpoints, enforce rate limiting, and employ endpoint detection solutions that can flag the distinctive behaviors of PoeLLM.

While the full scope of the campaign remains under investigation, early indicators suggest a rapid expansion as more AI platforms become publicly reachable. Security teams are urged to stay vigilant, update threat intelligence feeds, and collaborate with AI service providers to close gaps before attackers can repurpose the infrastructure for other malicious purposes.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related