"Compromised hosts are reused to expand the botnet," Lumen Black Lotus Labs said in a report shared with The Hacker News.
PoeLLM's poem-based command-and-control
The malware family identified in the report has been codenamed PoeLLM because of a deliberately unusual technique: the operators hide the command-and-control (C2) address inside a poem hosted in a public GitHub repository (github[.]com/ejejejdfbbebe). The first commit to that repository occurred on April 13, 2026. "Each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words," Ryan English, information security engineer at Lumen Technologies, told The Hacker News.
Targets: LiteLLM, Gotenberg, Gitea and Ivanti Sentry appliances
The campaign has focused on exposed, internet-facing deployments associated with AI and developer tooling. Lumen Black Lotus Labs reported the attacks primarily single out LiteLLM and Gotenberg, as well as Gitea and Ivanti Sentry appliances. The report frames this targeting as deliberate: the actors seek systems that combine accessible network exposure with substantial compute resources.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildScale, timeline, and geographic concentration
Evidence indicates the campaign has been active since April 2026, with more than 3,400 victim servers identified so far. At its operational peak in mid-June, the campaign involved almost 2,200 affected servers and saw nearly 800 active infections per day. Infections are concentrated in the U.S. and Western Europe, according to the Lumen analysis shared with The Hacker News.
Malware behavior: scanners, exploit servers, miners and Kryptex
Once it gains a foothold, PoeLLM installs cryptocurrency miners—Lumen observed XMRig and Iron deployed on compromised hosts—and connects victims to Kryptex, a Russian cryptocurrency mining service. The attackers repurpose some compromised systems to act as scanners and exploit servers, using them to discover additional vulnerable systems and to send HTTP POST requests to exposed ports on targets that instruct those systems to download the malware from the C2. Lumen also noted traffic toward SSH and other login portals that "suggests experimentation with distributed brute-force attacks; that capability’s maturity remains uncertain."
Attribution and endgame
Lumen Black Lotus Labs attributed the activity to an Italian-speaking threat actor with moderate confidence, citing Italian-language artifacts and netflow indicators. The report frames the campaign’s end goal succinctly: weaponize known vulnerabilities in publicly exposed services to enlist them in a cryptocurrency mining botnet, and convert a subset of those systems into scanners to expand the victim pool. As Lumen put it, "AI infrastructure is becoming an attractive target" because exposed AI/LLM services "are valuable not only because of software vulnerabilities, but also because they may contain useful data and run on powerful hardware suitable for mining."
What this means for technologists and affected enterprises
- Technologists and security teams: Expect compromised AI/LLM services to be reused as scanners and exploit platforms; monitoring for unusual scanning behavior and outbound connections to mining services such as Kryptex may reveal secondary abuse even after initial payloads are removed.
- Affected enterprises and procurement leaders: Publicly exposed instances of LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances are explicit examples in this campaign—organizations operating those services should prioritize hardening and exposure controls to limit the chance their compute resources are co-opted for illicit mining.
The PoeLLM campaign combines an imaginative C2 concealment method with straightforward monetization: turn powerful, exposed servers into miners and then use them to find more victims. The actors’ experimentation with distributed brute-force techniques, the reuse of compromised hosts as scanning and exploitation infrastructure, and the geographical concentration in the U.S. and Western Europe together create a clear profile of opportunistic, scalable abuse. Whether the brute-force experimentation matures and how defenders will adapt to the poem-driven C2 mechanism are open questions the observable facts leave for security teams to answer.
Read the original report at The Hacker News: https://thehackernews.com/2026/10/poellm-malware-infects-3400-servers-to.html




