Researchers at Lumen's Black Lotus Labs say PoeLLM has compromised more than 2,100 servers, with peak activity reaching as many as 800 infected systems active on a single day.
Scale and geographic reach: 2,100+ servers, United States and Western Europe
Black Lotus Labs (BLL) researchers tracking the botnet-style malware report that PoeLLM has been active since at least April and has significantly increased activity since then. BLL observed more than 2,100 compromised servers overall and noted peak daily activity on the order of 800 infected systems. The operation targeted systems across the United States and Western Europe, and researchers identified at least 11 command-and-control (C2) servers spun up by the operator to date.
Technique: poem-based C2 via a GitHub-hosted 'dash.css' file
PoeLLM uses an uncommon and deliberately obfuscated method to discover its C2 addresses. BLL found an ELF file named libgcrypt that retrieves four words or phrases from a poem titled “On the Nature of Connection” in a file named ‘dash.css’ hosted in a GitHub repository that appears to fork Node.js. The malware maps those words to numbers with a hard-coded dictionary and generates an IPv4 address corresponding to the C2. BLL observed the operator changing the poem to rotate C2 addresses—BLL counted 11 poem modifications so far and said another update is likely.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTargets and vulnerabilities: LiteLLM, Ollama, Gotenberg, Gitea, Ivanti Sentry
BLL identified many victims running exposed AI and developer tools, including LiteLLM and Ollama, the Gotenberg PDF converter, and the Gitea development toolkit. The researchers also uncovered signs of Ivanti Sentry targeting. BLL highlights that AI/LLM implementations are attractive for attackers because they are often poorly configured, exposed online, and typically run on powerful GPU clusters that are suitable for cryptomining.
Payloads, propagation and CVE chaining: miners, remote shell, port scanning
Once it compromises a host, PoeLLM turns the server into a scanner and exploit launchpad. BLL documented remote-shell functionality, integration of XMRig and Iron cryptocurrency miners, HTTP/S scanning, and exploit deployment capabilities. Infected systems communicated with a Russian crypto‑mining service called Kryptex, according to the researchers.
The malware performs scanning specifically on ports 3000 and 4000—ports associated with Gotenberg and LiteLLM—and attempts to exploit CVE-2026-42271. BLL describes CVE-2026-42271 as a vulnerability impacting LiteLLM’s MCP server test endpoints that was originally disclosed as requiring authentication and given a high-severity score. Horizon.ai researchers confirmed CVE-2026-42271 can be chained with CVE-2026-48710 to achieve unauthenticated remote code execution (RCE).
Infrastructure reuse and attribution: compromised routers and an Italian link
In analysing the botnet infrastructure, BLL found several C2 servers that featured vulnerable router administration interfaces, suggesting the attacker reused compromised routers as part of the control network. Although researchers could not make a confident attribution, they assessed with moderate confidence that the operator is Italian, drawing that judgment from comments embedded in the malware and an Italy‑based server hosting an administrative interface.
What system administrators, enterprise operators, and router administrators should do
- System administrators: BLL recommends applying the latest security updates, reducing public internet exposure for critical assets, and restricting external access only to trusted IPs.
- Enterprise operators running AI/LLM services: inspect network monitoring logs for anomalous scanning and connections to indicators of compromise (IoCs) shared by Black Lotus Labs, and review exposed ports such as 3000 and 4000 used by Gotenberg and LiteLLM.
- Router administrators and ISPs: investigate router administration interfaces for compromise, given BLL’s finding that some C2 servers were on routers with vulnerable admin panels and may have been repurposed by the operator.
PoeLLM combines novel operational craft—the poem-based C2 lookup—with familiar criminal goals: turning powerful, exposed infrastructure into disposable cryptomining nodes. BLL’s findings stress two practical realities: operators can iterate quickly (BLL observed 11 poem updates and 11 C2 servers), and defenders should treat exposed AI services as high-value targets that deserve the same hardening applied to more traditional internet-facing systems. For further technical details and the IoCs BLL shared, see the original BleepingComputer report.




