Skip to content
ittechwire

Technology news, clearly sourced

  1. Home
  2. Security

Security

PoeLLM malware hides its C2 address in a GitHub poem and hijacks exposed AI servers for mining

Lumen's Black Lotus Labs says the PoeLLM malware has infected more than 3,400 exposed AI and development servers since April, mining cryptocurrency and locating its command server through words in a poem on GitHub.

ittechwire Editorial5 min readSources: 3
Rows of white server racks with perforated doors along an aisle in a data center
PiDatacenters · CC BY-SA 4.0

Key points

  1. 1Black Lotus Labs says PoeLLM has infected more than 3,400 servers since April 2026, mostly in the United States and Western Europe; The Register reports more than 3,000.
  2. 2The malware builds its command-and-control address from four words in a poem stored on GitHub; the operator has edited the poem 11 times to move servers.
  3. 3Targets include exposed LiteLLM, Ollama, Gotenberg and Gitea servers, with signs of Ivanti Sentry targeting; infected hosts scan for and attack new victims.
  4. 4Compromised machines mine cryptocurrency with XMRig and Iron and connect to the Russian mining service Kryptex.
  5. 5The researchers link the campaign to an Italian-speaking actor with moderate confidence; administrators are advised to patch, limit internet exposure and check for the published indicators.

Full story

Researchers at Lumen's Black Lotus Labs have documented a malware family they call PoeLLM, which breaks into internet-facing AI and LLM servers, installs cryptocurrency miners and then uses the hijacked machines to hunt for further victims. The researchers named the financially motivated campaign Canto Incognito. According to The Hacker News and BleepingComputer, more than 3,400 servers have been infected since the activity started in April 2026; The Register, citing the same researchers, puts the figure at more than 3,000. BleepingComputer notes that the version of the report it first received gave 2,100 compromised servers, a number the researchers later raised in the published report.

The malware's name refers to how it finds its command-and-control server. According to the researchers, the operator keeps a poem titled "On the Nature of Connection" in a file called dash.css, inside a GitHub repository that is a fork of the Node.js website source. PoeLLM, an ELF binary named libgcrypt according to BleepingComputer, reads four words or phrases from fixed positions in that poem, turns them into numbers with a dictionary built into its code and assembles an IPv4 address from them. To switch servers, the operator only has to edit a few words. The first commit was made on April 13, 2026, and the poem has been changed 11 times since, The Register and BleepingComputer report. Black Lotus Labs told The Register that the text carries no links, downloads or encrypted strings that would mark it as malicious, that the technique was a first for the team, and that it believes the poem itself was written by AI.

Once installed, PoeLLM runs the XMRig and Iron miners and connects victims to Kryptex, which The Hacker News and BleepingComputer describe as a Russian mining service. It also carries remote-shell, scanning and exploit functions. According to BleepingComputer, infected hosts scan ports 3000 and 4000, which are associated with Gotenberg and LiteLLM, and try to exploit CVE-2026-42271, a flaw in LiteLLM's MCP server test endpoints that was first disclosed as requiring authentication; Horizon.ai researchers say it can be chained with CVE-2026-48710 for unauthenticated remote code execution. Most victims were running exposed versions of LiteLLM and Ollama, according to The Register, while hundreds ran the Gotenberg PDF converter or the Gitea development platform. The Register adds that Black Lotus Labs first spotted the malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. Victims are concentrated in the United States and Western Europe.

Black Lotus Labs attributes the campaign with moderate confidence to an Italian-speaking actor, citing Italian comments in the malware and on the attacker's GitHub pages as well as netflow data; BleepingComputer adds that the administrative interface was hosted on a server in Italy. Several C2 servers exposed vulnerable router administration pages, which the researchers read as a sign that the attacker reused compromised routers. The Hacker News quotes the company as saying the campaign peaked in mid-June with almost 2,200 affected servers, nearly 800 of them active per day, and that newer traffic aimed at SSH and other login pages points to experiments with distributed brute-force attacks whose maturity is still unclear. For defence, BleepingComputer advises administrators to install current security updates, keep critical systems off the public internet where possible, limit external access to trusted IP addresses and search network logs for connections to the indicators of compromise published by Black Lotus Labs.

The researchers say AI infrastructure draws attackers not only through software flaws but also because such servers may hold useful data and often run on GPU hardware suited to mining. They told The Register that the campaign appears unusual in going after several AI-related services at once, whereas the LiteLLM supply chain compromise this year focused on one service and affected roughly 2,500 victims according to open sources. Black Lotus Labs said it expects more attacks of this kind, arguing that AI tools make it easier to set up services such as LiteLLM, Ollama or Gotenberg without checking that they are patched and protected.

Why it matters

According to Black Lotus Labs, AI and LLM deployments are often poorly configured, reachable from the internet and backed by GPU clusters, which makes them useful both for mining and as a base for further attacks. The poem technique also complicates defence: a public GitHub file without links or encrypted content is hard to flag, and lists of known C2 addresses can go stale each time the operator edits the poem. Teams running LiteLLM, Ollama, Gotenberg or Gitea have reason to check whether these services need to be publicly reachable at all.

Timeline

  1. · Published

Topics#malware#cryptojacking#botnet#LiteLLM#AI security

Sources

This story draws on the following sources. Read them for full context.

  1. 1The Hacker News · News reportPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnetthehackernews.com
  2. 2The Register · News reportPoetry is the new AI security threat as PoeLLM malware infects 3K+ serverswww.theregister.com
  3. 3BleepingComputer · News reportPoeLLM malware infects exposed AI servers in cryptomining attackswww.bleepingcomputer.com