• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
Technology
Report

PoeLLM malware reportedly hits more than 3,400 servers in crypto-mining campaign

DailyDarkWeb, citing Lumen’s Black Lotus Labs, says four keywords in a GitHub poem reveal the malware’s command-server address.

T3KN05H4M4NT3
Dark Web IntelligenceDW
2 Sources, 1h ago, first seen 1h ago

TLDR

DailyDarkWeb, citing Lumen’s Black Lotus Labs, reports that PoeLLM has infected more than 3,400 servers since April 2026, mostly vulnerable internet-facing LiteLLM, Ollama, Gotenberg and Gitea deployments. The malware uses keywords in a GitHub poem to find its command server. Infected hosts mine cryptocurrency and scan for new victims. Lumen says a vulnerable LiteLLM endpoint was likely an exploitation path.

Combined views

1.9K

2 Sources, first seen 1h ago

6 likes3 reposts

Combined views

1.9K

2 Sources, first seen 1h ago

6 likes3 reposts

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

2 Sources

T3KN05H4M4N@T3KN05H4M4NPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet https://share.google/I1yas8BKMr68DMfTr1h
Dark Web Intelligence@DailyDarkWeb🚨 POELLM BOTNET INFECTS 3,400+ EXPOSED AI AND DEV SERVERS, HIDES ITS C2 ADDRESS IN A POEM ON GITHUB Lumen's Black Lotus Labs says the PoeLLM malware has hit more than 3,400 servers since April 2026, mostly vulnerable internet-facing LiteLLM, Ollama, Gotenberg and Gitea deployments, with possible targeting of Ivanti Sentry. Most victims are in the US and Western Europe. • The malware works out its C2 IP address from four keywords in a poem kept in a GitHub repository. The actor has edited the poem 11 times since April 13, each time pointing the bots to a new server • Infected hosts mine cryptocurrency with XMRig and Iron and are reused to scan for and exploit new victims • Several C2 servers ran on hijacked routers with vulnerable admin pages • Lumen says a LiteLLM endpoint tied to command-injection flaw CVE-2026-42271 was likely the exploitation path • Lumen links PoeLLM to an Italian-speaking actor, says the campaign appears financially motivated, and has blocked traffic to and from its C2 servers ⚠️ Analyst Note: Activity peaked at roughly 800 active bots a day. Self-hosted AI services combine known bugs with powerful hardware, which makes them attractive mining targets. Keep LiteLLM, Ollama, Gotenberg and Gitea patched and off the open internet, and check network logs against the IOCs Lumen published. Source: https://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malware #DDW #DarkWeb #CyberSecurity #Botnet #Malware #AISecurity #Cryptomining58m
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI

    2 Sources

    T3KN05H4M4N@T3KN05H4M4NPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet https://share.google/I1yas8BKMr68DMfTr1h
    Dark Web Intelligence@DailyDarkWeb🚨 POELLM BOTNET INFECTS 3,400+ EXPOSED AI AND DEV SERVERS, HIDES ITS C2 ADDRESS IN A POEM ON GITHUB Lumen's Black Lotus Labs says the PoeLLM malware has hit more than 3,400 servers since April 2026, mostly vulnerable internet-facing LiteLLM, Ollama, Gotenberg and Gitea deployments, with possible targeting of Ivanti Sentry. Most victims are in the US and Western Europe. • The malware works out its C2 IP address from four keywords in a poem kept in a GitHub repository. The actor has edited the poem 11 times since April 13, each time pointing the bots to a new server • Infected hosts mine cryptocurrency with XMRig and Iron and are reused to scan for and exploit new victims • Several C2 servers ran on hijacked routers with vulnerable admin pages • Lumen says a LiteLLM endpoint tied to command-injection flaw CVE-2026-42271 was likely the exploitation path • Lumen links PoeLLM to an Italian-speaking actor, says the campaign appears financially motivated, and has blocked traffic to and from its C2 servers ⚠️ Analyst Note: Activity peaked at roughly 800 active bots a day. Self-hosted AI services combine known bugs with powerful hardware, which makes them attractive mining targets. Keep LiteLLM, Ollama, Gotenberg and Gitea patched and off the open internet, and check network logs against the IOCs Lumen published. Source: https://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malware #DDW #DarkWeb #CyberSecurity #Botnet #Malware #AISecurity #Cryptomining58m
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet