PoeLLM malware infects exposed AI servers in cryptomining attacks

Refract AI Intelligence Digest

BLUF

Exposed AI infrastructure is being weaponized for cryptomining and lateral movement via PoeLLM malware.

NEWS

A new campaign identified by BleepingComputer utilizes PoeLLM malware to compromise publicly accessible AI services. Infected servers are repurposed as mining rigs and scanning tools to identify additional vulnerabilities. The attack leverages the computational power of AI hardware for illicit profit and network expansion.

Why I Care

Organizations deploying public-facing AI models face increased risk of resource theft and infrastructure compromise. This trend highlights the growing convergence of AI operations and traditional cyber threats, potentially leading to service degradation and data exposure.

Next Steps

Security teams should audit external AI endpoints for unauthorized access immediately. Implement strict network segmentation and authentication for all AI services by end of week. Monitor system resources for unusual CPU/GPU usage indicative of cryptomining activity.

A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.