Follow
Subscribe via Email!

Enter your email address to subscribe to this platform and receive notifications of new posts by email.

Lumen Uncovers PoeLLM Malware Hijacking Exposed AI Servers

Cybersecurity researchers at Lumen Black Lotus Labs discovered PoeLLM malware, a cryptomining threat that targets exposed AI servers and extracts command addresses from GitHub poetry.
An illustration of black ravens and human skulls over a blue gradient background.

Security researchers at Lumen Technologies uncovered a financially motivated botnet campaign that uses PoeLLM malware to compromise exposed artificial intelligence servers, the company reported on October 7 [2]. Intruders target internet-facing machine learning tools and developer services to deploy cryptocurrency miners. The botnet has compromised more than 3,400 servers since April 2026 by hiding command addresses inside online poetry [1].

How PoeLLM Malware Hijacks Exposed Hosts

The campaign, dubbed Canto Incognito by Lumen Black Lotus Labs, focuses on enterprise systems that run publicly reachable machine learning software [2]. Intruders search across the open web for exposed deployments of LiteLLM and Ollama, as well as coding tools like the Gitea toolkit and Ivanti Sentry appliances [1]. Once hackers break in, they install rogue mining programs like XMRig and Iron to siphon server compute power for illicit financial profit. The threat crew targeted compute [2].

Lumen analysts found that the threat actors don’t stop at mining digital coins on the systems they compromise during an intrusion [2]. Instead, they turn each captured machine into a springboard to hunt down more victims on public networks [1]. “Compromised hosts are reused to expand the botnet,” Lumen Black Lotus Labs said in a report shared with The Hacker News. “Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems” [2]. This automated expansion strategy lets the botnet spread on its own across public networks without needing the attacker to run every port scan from a single centralized operations point [1].

Activity began in April 2026. Botnet activity hit its highest point around the middle of June 2026. During that peak window, roughly 2,200 affected servers were compromised, while nearly 800 systems remained active on any single day [2]. An early briefing listed 2,100 compromised hosts, but subsequent verification confirmed that more than 3,400 systems suffered infections in the United States and Western Europe [1].

Screenshot from Black Lotus Labs detailing the PoeLLM malware infrastructure.
Security analysts documented the operational workflow of the botnet across compromised endpoints. (Credit: Black Lotus Labs)

Hiding Control Addresses Inside GitHub Poetry

The malware uses an unusual method to learn where to send data and receive instructions from its operators, bypassing conventional blocklists that catch static numerical pointers. To hide the control channel, the threat actors built an ELF binary named libgcrypt that looks up its command-and-control server by parsing text hosted in a public GitHub code repository that appears to fork Node.js. The repository holds a stylesheet named ‘dash.css’ that contains a poem titled “On the Nature of Connection” [1]. The first commit was April 13, 2026 [2].

Rather than storing a fixed web address in the binary, the malware extracts four specific words or phrases from the lines of the poem, converting them into numbers through a hard-coded dictionary compiled into the software. Those numbers assemble into a valid IPv4 address for the command server [1]. Ryan English, information security engineer at Lumen Technologies, told The Hacker News: “Each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words” [2].

Black Lotus Labs observed that the operator modified the poem 11 times during the campaign, setting up at least 11 control points. Several control servers ran on hacked home routers, proving that the crew reuses consumer gear to mask control traffic while evading monitoring systems [1].

Global map showing geographic distribution of compromised servers in the United States and Western Europe.
Infections were concentrated heavily across server clusters in the United States and Western Europe. (Credit: Black Lotus Labs)

PoeLLM Botnet Spreads Through Vulnerability Scanning

After infecting a host, the botnet equips the machine with scanning tools and exploit payloads to discover more victims across public internet ranges on ports 3000 and 4000, which are commonly associated with Gotenberg and LiteLLM services [1]. When the scanner detects an open service on either port, it sends an HTTP POST request that instructs the remote machine to pull the malicious binary down from the active control server [2]. Attackers also probe web services much like when hackers exploit a critical flaw for code execution on untrusted inputs [1].

A key weapon in the operator toolkit is an exploit targeting CVE-2026-42271, a security bug located in test endpoints for LiteLLM Model Context Protocol (MCP) servers. Security analysts originally disclosed the bug as an authenticated flaw with a high severity rating. However, researchers at Horizon.ai confirmed that attackers can chain this issue with CVE-2026-48710 to achieve unauthenticated remote code execution across vulnerable server deployments without requiring any valid user credentials or account authentication. That exploit chain lets threat actors run arbitrary system commands on exposed setups [1].

Beyond port scanning and software exploits, Black Lotus Labs detected recent network traffic directed at SSH ports and login portals, which suggests tests with distributed brute-force password guessing. Analysts said that the overall maturity of this brute-force capability isn’t certain, but it indicates that the attackers want diverse entry paths. If an exposed system runs an accessible remote shell, the botnet can attempt to force its way inside [2].

Code snippet showing the poem used for command and control address construction.
The threat actor modified four words in a hosted poem to generate changing IPv4 server addresses. (Credit: Black Lotus Labs)

Can Threat Actors Abuse Powerful Hardware?

Why do cybercriminals focus so much energy on hijacking systems that run machine learning frameworks? The answer comes down to raw compute capacity and loose default setups on public servers [1]. “AI infrastructure is becoming an attractive target,” Lumen said. “Exposed AI/LLM services are valuable not only because of software vulnerabilities, but also because they may contain useful data and run on powerful hardware suitable for mining” [2]. Graphics processing units built for artificial intelligence provide strong math throughput for mining crypto. Because machine learning tasks demand powerful GPU clusters to handle matrix math, compromising these hosts allows intruders to generate crypto much faster than standard cloud virtual machines would ever permit [1].

Many coding teams set up AI tools like Ollama or LiteLLM in temporary cloud environments for testing and forget to restrict access. These setups often lack firewall boundaries or strong authentication, leaving them visible to automated internet port scanners [1]. At the same time, threat actors can look through server file systems for API keys, training datasets, and software code [2].

Analysts at Lumen tracked the identity of the group behind the operation and found several clues pointing to a European origin [2]. Black Lotus Labs assessed with moderate confidence that the operator is an Italian-speaking individual or group, citing Italian-language comments embedded inside the malware source code as well as an admin interface hosted on an Italian server [1]. Network flow patterns observed during the audit also pointed toward Italian infrastructure, though attribution in botnet inquiries can’t reach absolute certainty [2].

Diagram illustrating the attack overview and server compromise lifecycle.
Compromised systems were repurposed into active scanners to identify and infect additional hosts. (Credit: Black Lotus Labs)

Defending Network Perimeters Against PoeLLM Attacks

Halting the spread of the botnet needs system administrators to tighten access to machine learning tools and network services by promptly patching known bugs, particularly the LiteLLM test endpoint flaw tracked under CVE-2026-42271. Applying current software updates removes the remote code execution path that hackers rely on to infect systems. Because software vendors regularly publish security releases to address disclosed vulnerabilities, keeping software packages up to date forms the most reliable barrier against automated exploitation scripts [1].

Beyond applying software patches, network administrators should audit which local services have exposure to the wider internet. Services like Gotenberg PDF converter, LiteLLM proxy servers, and code repositories don’t need direct exposure to public traffic. Placing these services behind a virtual private network or restricting inbound traffic exclusively to trusted IP addresses stops scanners from discovering them [1].

Finally, security engineers should inspect network monitoring logs for connections to indicators of compromise released by Black Lotus Labs [1]. Outbound traffic directed toward known C2 IP addresses or Russian mining pools like Kryptex signals an active infection. Checking local process trees for unauthorized instances of XMRig or Iron can help engineers identify compromised clusters before attackers establish persistence. Both miners run in user space [2].

Sources
  1. ONLINE NEWS Toulas, B. (2026, October 7). PoeLLM malware infects exposed AI servers in cryptomining attacks. BleepingComputer. [Article Link]
  2. ONLINE NEWS The Hacker News. (2026, October 7). PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet. The Hacker News. [Article Link]
  3. ONLINE NEWS Lyons, J. (2026, October 7). Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers. The Register. [Article Link]

Leave a Comment

Related Posts
Total
0
Share