// AI threat desk · 8 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesHighAICVSS not assigned

Exposed AI services targeted by Lumen-tracked PoeLLM campaign

PoeLLM targets exposed AI and enterprise services to deploy miners and expand a botnet, affecting more than 3,400 servers. Lumen’s Black Lotus Labs disclosed the campaign.

AI-generated image of security analysts monitoring servers and blurred cybersecurity dashboards in a dim operations centre.
AI-generated image, not a photo of the event.
Key takeaways
  • PoeLLM targets exposed AI and LLM infrastructure to deploy cryptocurrency miners and expand a botnet.
  • The campaign has impacted more than 3,400 victim servers and exceeded 800 active servers per day at its peak.
  • Compromised hosts are reused as scanners and exploit servers to find and compromise additional vulnerable systems.

Lumen’s Black Lotus Labs said the PoeLLM malware campaign is targeting exposed AI and large language model infrastructure to deploy cryptocurrency miners and expand a botnet. The campaign has impacted more than 3,400 victim servers, with peak activity exceeding 800 active servers per day.

The campaign primarily affects vulnerable internet-facing LiteLLM, Ollama, Gotenberg and Gitea deployments, with possible targeting of Ivanti Sentry. Compromised hosts become scanners and exploit servers that help the operator find and compromise additional vulnerable systems.

The activity matters to organizations running internet-facing AI and enterprise services because exposed AI services can provide access to data and computing resources. Lumen assessed that PoeLLM is associated with an Italian-speaking threat actor and is deployed by exploiting publicly exposed services.

On this page

PoeLLM hides its command server in a GitHub poem

PoeLLM derives its current command-and-control server from keywords in a poem hosted in a GitHub repository. The four extracted words are converted into numbers, which are combined to form the IPv4 address hosting the command-and-control server.

The Register said the poem had no links, downloadable files or easily flagged encrypted text. It also reported that Black Lotus Labs called the technique its first observed real-world case of “adversarial poetry,” an AI jailbreak technique that turns harmful prompts into poems to bypass safety guardrails.

The campaign used miners and expanded through exposed services

The campaign appears financially motivated. PoeLLM deploys the XMRig and Iron cryptocurrency miners and connects victims to Kryptex mining infrastructure.

Lumen first encountered the PoeLLM infrastructure while investigating the Ivanti Sentry vulnerability CVE-2026-10520.

The operator began broader scanning and exploitation in May, particularly against exposed LiteLLM and Gotenberg services. At the peak of operations in mid-June, the campaign involved almost 2,200 affected servers and nearly 800 active servers per day.

Lumen linked PoeLLM to an Italian-speaking threat actor

The Register reported that Black Lotus Labs attributed the malware to an Italian-speaking criminal. It said Black Lotus Labs named the financially motivated campaign Canto Incognito because it hides malicious commands in a poem posted to a GitHub repository.

The Register reported that most victims were running vulnerable, internet-facing LiteLLM and Ollama systems, while hundreds were running Gotenberg, a PDF converter, and Gitea, a software development platform.

Lumen said Black Lotus Labs blocked all traffic to and from PoeLLM command-and-control servers and will continue monitoring for new traffic. It also said Lumen Defender customers had been protected from PoeLLM servers since the malware was discovered.

Lumen recommends inspecting network monitoring logs for connections to indicators of compromise associated with PoeLLM. More recent traffic toward SSH and other login portals suggested experimentation with distributed brute-force attacks, but the maturity of that capability remained uncertain.

What to do now

  1. Continuously audit external exposure after installing new open-source tools and restrict required service ports to outside access to the maximum extent possible.

FAQ

What is the PoeLLM malware campaign?

It is a campaign targeting exposed AI and LLM infrastructure to deploy cryptocurrency miners and expand a botnet.

Which services does PoeLLM target?

The campaign primarily affects vulnerable internet-facing LiteLLM, Ollama, Gotenberg and Gitea deployments, with possible targeting of Ivanti Sentry.

How many servers did PoeLLM affect?

Lumen said the malware impacted more than 3,400 victim servers, with peak activity exceeding 800 active servers per day.

How does PoeLLM find its command-and-control server?

It extracts four words from a poem hosted on GitHub, converts them into numbers and combines them into the IPv4 address of the command-and-control server.

Has Lumen blocked PoeLLM traffic?

Yes. Lumen said Black Lotus Labs blocked all traffic to and from PoeLLM command-and-control servers and that Lumen Defender customers had been protected since discovery.

Sources

  1. Canto incognito: tracking the PoeLLM malware, LumenPrimary
  2. PoeLLM malware infects exposed AI servers in cryptomining attacks, BleepingComputer
  3. Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers, The Register
How we checked this story
ClaimSourceStatus
The PoeLLM malware campaign targets exposed AI and LLM infrastructure to deploy cryptocurrency miners and expand a botnet.LumenConfirmed
The campaign primarily affects vulnerable internet-facing LiteLLM, Ollama, Gotenberg and Gitea deployments, with possible targeting of Ivanti Sentry.LumenConfirmed
PoeLLM derives its current command-and-control server from keywords in a GitHub-hosted poem.LumenConfirmed
PoeLLM deploys XMRig and Iron cryptocurrency miners and connects victims to Kryptex mining infrastructure.LumenConfirmed
Compromised hosts become scanners and exploit servers that help the actor find and compromise additional vulnerable systems.LumenConfirmed
The malware has impacted more than 3,400 victim servers, with peak activity exceeding 800 active servers per day.LumenConfirmed
Lumen assessed that PoeLLM is associated with an Italian-speaking threat actor and is deployed through exploitation of publicly exposed services.LumenConfirmed
Lumen first encountered the PoeLLM infrastructure while investigating Ivanti Sentry vulnerability CVE-2026-10520.LumenConfirmed
The operator began broader scanning and exploitation in May, particularly against exposed LiteLLM and Gotenberg services.LumenConfirmed
At the peak of operations in mid-June, the campaign involved almost 2,200 affected servers and nearly 800 active servers per day.LumenConfirmed
More recent traffic toward SSH and other login portals suggested experimentation with distributed brute-force attacks, but the capability’s maturity remained uncertain.LumenConfirmed
The malware’s four extracted poem words are converted into numbers that form the IPv4 address hosting the command-and-control server.LumenConfirmed
Lumen blocked all traffic to and from PoeLLM command-and-control servers and said Lumen Defender customers had been protected since discovery.LumenConfirmed
Lumen recommends inspecting monitoring logs for indicators of compromise associated with PoeLLM.LumenConfirmed
BleepingComputer reported that PoeLLM turns compromised AI servers into scanners and exploit launchpads.BleepingComputerAttributed
The Register reported that the campaign infected more than 3,000 servers since April and used compromised systems to mine cryptocurrency and expand its botnet.The RegisterAttributed
The Register reported that Black Lotus Labs called this its first observed real-world case of adversarial poetry.The RegisterAttributed
The Register reported that the poem contained no links, downloadable files or easily flagged encrypted text.The RegisterAttributed
The Register reported that PoeLLM primarily affected vulnerable internet-facing LiteLLM and Ollama systems, with hundreds of victims running Gotenberg and Gitea.The RegisterAttributed

Could not verify

  • Whether the campaign has been exploited by other actors is not established.
  • How many organizations or individuals were behind the campaign is not established.
  • Whether the reported Italian-speaking actor is the malware developer is not established.
  • Whether the related vulnerabilities were exploited in every reported infection is not established.
Explore with AI