PoeLLM botnet hides C2 in a poem, infects 3,400+ exposed AI servers
Lumen's Black Lotus Labs says the PoeLLM malware has compromised more than 3,400 servers, including LiteLLM and Ollama hosts, to mine cryptocurrency and spread further.
At a glance
- Black Lotus Labs counts more than 3,400 compromised servers since April 2026, with up to 800 active in a single day.
- Targets include exposed LiteLLM, Ollama, Gotenberg and Gitea deployments, with signs of Ivanti Sentry targeting.
- The malware derives its C2 address from words in a poem hosted on GitHub, letting the operator change servers by editing the text.
- Infected hosts install XMRig and Iron miners and are reused to scan for and exploit new victims.
A financially motivated botnet called PoeLLM has compromised more than 3,400 servers, many of them running exposed AI tooling, to mine cryptocurrency and expand its reach, Lumen's Black Lotus Labs (BLL) said in a report published on October 7. According to BleepingComputer, the malware has been active since at least April 2026, with up to 800 infected systems active on a single day, mostly in the United States and Western Europe. The Hacker News reports that Lumen calls the campaign Canto Incognito.
What happened
BLL found that many victims run internet-facing AI and developer tools such as LiteLLM and Ollama, the Gotenberg PDF converter and the Gitea code hosting platform, and also saw signs of Ivanti Sentry appliances being targeted. According to The Hacker News, activity peaked in mid-June, when nearly 2,200 servers were affected. "AI infrastructure is becoming an attractive target," Lumen said.
Technical details
BleepingComputer reports that PoeLLM is an ELF binary named libgcrypt. Instead of hard-coding its command-and-control (C2) address, it fetches four words from a poem titled "On the Nature of Connection" stored in a dash.css file in a GitHub repository that appears to fork Node.js, then converts those words into an IPv4 address with a built-in dictionary. To move to new infrastructure, the operator simply edits the poem; BLL has observed 11 such edits and at least 11 C2 servers.
The malware provides a remote shell, deploys the XMRig and Iron cryptocurrency miners, and connects victims to the Russian mining service Kryptex. Compromised servers become scanners that probe ports 3000 and 4000, associated with Gotenberg and LiteLLM, and try to exploit CVE-2026-42271 in LiteLLM's MCP server test endpoints. Horizon3.ai found that this flaw, originally described as requiring authentication, can be chained with CVE-2026-48710 for unauthenticated remote code execution, according to BleepingComputer. Lumen also observed recent traffic suggesting experiments with distributed SSH brute-forcing.
BLL assessed with moderate confidence that the operator is Italian-speaking, based on comments in the malware and an Italy-based server hosting the administration panel.
What to do
BLL recommends applying the latest security updates, reducing public internet exposure of critical assets, restricting external access to trusted IP addresses and reviewing network logs for connections to the indicators of compromise published in its report. Teams running LiteLLM, Ollama, Gotenberg or Gitea should make sure these services are not directly reachable from the internet, keep LiteLLM on the latest release, and watch for unexpected CPU load, unknown libgcrypt processes and outbound connections to mining pools.
Related CVEs
Sources
- PoeLLM malware infects exposed AI servers in cryptomining attacks — BleepingComputer
- PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet — The Hacker News
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



