Skip to main content
Discover what's not being covered
Published • loading... • Updated

PoeLLM malware infects exposed AI servers in cryptomining attacks

Researchers said the botnet has compromised more than 2,100 servers and uses a poem-based lookup to rotate hidden command-and-control addresses.

  • On Wednesday, Black Lotus Labs reported that PoeLLM malware has compromised more than 3,400 servers since April. The botnet uses a GitHub-hosted poem to hide command-and-control server addresses.
  • Researchers identified the campaign as Canto Incognito, attributed to an Italian-speaking attacker. The malware extracts four specific words from a poem titled 'On the Nature of Connection' on GitHub, converting them into dynamic command-and-control addresses.
  • PoeLLM deploys XMRig and Iron miners, connecting compromised systems to Kryptex mining infrastructure. By targeting vulnerable AI services like LiteLLM and Ollama, the botnet turns infected servers into launchpads for further exploits.
  • At its peak, the malware infected more than 800 active servers daily, exploiting Ivanti Sentry and CVE-2026-42271. Victims running Gotenberg and Gitea also face risks as the botnet scans for additional vulnerable services.
  • Because the operator updates the poem to rotate command-and-control locations, the botnet maintains high resiliency. BLL recommends administrators apply security updates, reduce public internet exposure, and inspect network logs for suspicious connections.
Insights by Ground AI

12 Articles

BleepingComputerBleepingComputer
Reposted by
IT Security News - cybersecurity, infosecurity newsIT Security News - cybersecurity, infosecurity news
Center

PoeLLM malware infects exposed AI servers in cryptomining attacks

A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. [...]

·Melville, United States
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 75% of the sources are Center
75% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in Melville, United States on Wednesday, October 7, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal