PoeLLM Has Turned 3,400+ Exposed AI Servers Into a Crypto-Mining Botnet — Its Command-and-Control Address Hides in a Poem Hosted on GitHub
PoeLLM Has Turned 3,400+ Exposed AI Servers Into a Crypto-Mining Botnet — Its Command-and-Control Address Hides in a Poem Hosted on GitHub
Lumen's Black Lotus Labs has published research on a cryptomining campaign it calls Canto Incognito, built around a malware family named PoeLLM that has compromised more than 3,400 servers since April 2026. The targets are exposed AI and LLM infrastructure — LiteLLM and Ollama deployments above all, plus the Gotenberg PDF converter, the Gitea development toolkit, and likely Ivanti Sentry appliances. The malware is an ELF binary that masquerades as libgcrypt, mines cryptocurrency with XMRig and Iron, and converts each victim into a scanner and exploit server for recruiting the next one.
The command-and-control design is the signature. PoeLLM reads four words or phrases from a poem titled "On the Nature of Connection," hosted in a dash.css file in a GitHub repository that appears to fork Node.js, and maps them through a hard-coded dictionary to an IPv4 address. Rotating the C2 means rewriting the poem — the actor has done so eleven times, with the first commit landing on April 13. Traffic analysis ties victims to Kryptex, a Russian cryptomining service; infections concentrate in the United States and Western Europe, with a mid-June peak of roughly 2,200 affected servers and nearly 800 active in a single day. Several C2 servers themselves ran on compromised routers with vulnerable administration interfaces, and Lumen assesses with moderate confidence that the operator is Italian-speaking, based on language artifacts in the malware and an Italy-hosted administrative server.
The exploit side is concrete too. Compromised hosts scan for further victims on ports 3000 and 4000 — Gotenberg and LiteLLM territory — and attempt CVE-2026-42271, a flaw in LiteLLM's MCP server test endpoints originally disclosed as requiring authentication; Horizon3.ai researchers showed it chains with CVE-2026-48710 into unauthenticated remote code execution. More recent traffic toward SSH and other login portals suggests the actor is experimenting with distributed brute-force attacks. Lumen has blocked traffic to and from the known C2 servers for its customers, but the botnet keeps scanning, and each infected host widens its own victim pool by proxying attacks through compromised systems.
The economics explain the targeting: AI/LLM services are internet-exposed by habit, guarded by nobody in particular, and run on GPU hardware that mines beautifully. It's the second time this year LiteLLM's exposure has made news — CISA flagged the LiteLLM MCP auth bypass as actively exploited in a September KEV wave — and the pattern generalizes: every new AI service deployed at the edge is a high-value machine with a management interface and no operational security history.
What Should You Do?
- Patch the named stacks: LiteLLM deployments first — CVE-2026-42271 chained with CVE-2026-48710 is the documented entry path — plus current Ollama, Gotenberg and Gitea versions.
- Stop exposing inference endpoints: bind model proxies and their test endpoints to localhost or an internal network, and put whatever must be reachable behind an authenticated gateway.
- Hunt for the campaign's traces: unknown
libgcryptprocesses on servers that shouldn't have them, outbound connections to Kryptex infrastructure, GPU utilization that doesn't match your workloads, and unexpected egress to raw GitHub content. - Run GPU clusters as production infrastructure — EDR coverage, egress allow-listing and monitoring, not a lab profile that ends at "it has a firewall."
The WAF Angle
Exposed AI services have HTTP APIs, so the edge discipline is familiar: authenticate everything, restrict what doesn't need exposure, and watch the request shapes. A WAF or API gateway in front of LiteLLM-style model proxies is the modern version of a classic pattern — and CVE-2026-42271 lives in test endpoints, the exact kind of debug surface a gateway should block by default. The poem trick deserves its own respect: hiding the C2 inside content on a trusted domain means IP blocklists and domain reputation both fail, which is an argument for category-based egress control over host-based blocklisting. Defense here is layered the old-fashioned way: patch the software, hide the endpoint, and watch the compute bill — mining load you didn't buy is the loudest alarm this campaign can trip.