- PoeLLM targets exposed AI and LLM infrastructure to deploy cryptocurrency miners and expand a botnet.
- The campaign has impacted more than 3,400 victim servers and exceeded 800 active servers per day at its peak.
- Compromised hosts are reused as scanners and exploit servers to find and compromise additional vulnerable systems.
Lumen’s Black Lotus Labs said the PoeLLM malware campaign is targeting exposed AI and large language model infrastructure to deploy cryptocurrency miners and expand a botnet. The campaign has impacted more than 3,400 victim servers, with peak activity exceeding 800 active servers per day.
The campaign primarily affects vulnerable internet-facing LiteLLM, Ollama, Gotenberg and Gitea deployments, with possible targeting of Ivanti Sentry. Compromised hosts become scanners and exploit servers that help the operator find and compromise additional vulnerable systems.
The activity matters to organizations running internet-facing AI and enterprise services because exposed AI services can provide access to data and computing resources. Lumen assessed that PoeLLM is associated with an Italian-speaking threat actor and is deployed by exploiting publicly exposed services.
On this page
PoeLLM hides its command server in a GitHub poem
PoeLLM derives its current command-and-control server from keywords in a poem hosted in a GitHub repository. The four extracted words are converted into numbers, which are combined to form the IPv4 address hosting the command-and-control server.
The Register said the poem had no links, downloadable files or easily flagged encrypted text. It also reported that Black Lotus Labs called the technique its first observed real-world case of “adversarial poetry,” an AI jailbreak technique that turns harmful prompts into poems to bypass safety guardrails.
The campaign used miners and expanded through exposed services
The campaign appears financially motivated. PoeLLM deploys the XMRig and Iron cryptocurrency miners and connects victims to Kryptex mining infrastructure.
Lumen first encountered the PoeLLM infrastructure while investigating the Ivanti Sentry vulnerability CVE-2026-10520.
The operator began broader scanning and exploitation in May, particularly against exposed LiteLLM and Gotenberg services. At the peak of operations in mid-June, the campaign involved almost 2,200 affected servers and nearly 800 active servers per day.
Lumen linked PoeLLM to an Italian-speaking threat actor
The Register reported that Black Lotus Labs attributed the malware to an Italian-speaking criminal. It said Black Lotus Labs named the financially motivated campaign Canto Incognito because it hides malicious commands in a poem posted to a GitHub repository.
The Register reported that most victims were running vulnerable, internet-facing LiteLLM and Ollama systems, while hundreds were running Gotenberg, a PDF converter, and Gitea, a software development platform.
Lumen said Black Lotus Labs blocked all traffic to and from PoeLLM command-and-control servers and will continue monitoring for new traffic. It also said Lumen Defender customers had been protected from PoeLLM servers since the malware was discovered.
Lumen recommends inspecting network monitoring logs for connections to indicators of compromise associated with PoeLLM. More recent traffic toward SSH and other login portals suggested experimentation with distributed brute-force attacks, but the maturity of that capability remained uncertain.
What to do now
- Continuously audit external exposure after installing new open-source tools and restrict required service ports to outside access to the maximum extent possible.
FAQ
What is the PoeLLM malware campaign?
It is a campaign targeting exposed AI and LLM infrastructure to deploy cryptocurrency miners and expand a botnet.
Which services does PoeLLM target?
The campaign primarily affects vulnerable internet-facing LiteLLM, Ollama, Gotenberg and Gitea deployments, with possible targeting of Ivanti Sentry.
How many servers did PoeLLM affect?
Lumen said the malware impacted more than 3,400 victim servers, with peak activity exceeding 800 active servers per day.
How does PoeLLM find its command-and-control server?
It extracts four words from a poem hosted on GitHub, converts them into numbers and combines them into the IPv4 address of the command-and-control server.
Has Lumen blocked PoeLLM traffic?
Yes. Lumen said Black Lotus Labs blocked all traffic to and from PoeLLM command-and-control servers and that Lumen Defender customers had been protected since discovery.
Sources
How we checked this story
| Claim | Source | Status |
|---|---|---|
| The PoeLLM malware campaign targets exposed AI and LLM infrastructure to deploy cryptocurrency miners and expand a botnet. | Lumen | Confirmed |
| The campaign primarily affects vulnerable internet-facing LiteLLM, Ollama, Gotenberg and Gitea deployments, with possible targeting of Ivanti Sentry. | Lumen | Confirmed |
| PoeLLM derives its current command-and-control server from keywords in a GitHub-hosted poem. | Lumen | Confirmed |
| PoeLLM deploys XMRig and Iron cryptocurrency miners and connects victims to Kryptex mining infrastructure. | Lumen | Confirmed |
| Compromised hosts become scanners and exploit servers that help the actor find and compromise additional vulnerable systems. | Lumen | Confirmed |
| The malware has impacted more than 3,400 victim servers, with peak activity exceeding 800 active servers per day. | Lumen | Confirmed |
| Lumen assessed that PoeLLM is associated with an Italian-speaking threat actor and is deployed through exploitation of publicly exposed services. | Lumen | Confirmed |
| Lumen first encountered the PoeLLM infrastructure while investigating Ivanti Sentry vulnerability CVE-2026-10520. | Lumen | Confirmed |
| The operator began broader scanning and exploitation in May, particularly against exposed LiteLLM and Gotenberg services. | Lumen | Confirmed |
| At the peak of operations in mid-June, the campaign involved almost 2,200 affected servers and nearly 800 active servers per day. | Lumen | Confirmed |
| More recent traffic toward SSH and other login portals suggested experimentation with distributed brute-force attacks, but the capability’s maturity remained uncertain. | Lumen | Confirmed |
| The malware’s four extracted poem words are converted into numbers that form the IPv4 address hosting the command-and-control server. | Lumen | Confirmed |
| Lumen blocked all traffic to and from PoeLLM command-and-control servers and said Lumen Defender customers had been protected since discovery. | Lumen | Confirmed |
| Lumen recommends inspecting monitoring logs for indicators of compromise associated with PoeLLM. | Lumen | Confirmed |
| BleepingComputer reported that PoeLLM turns compromised AI servers into scanners and exploit launchpads. | BleepingComputer | Attributed |
| The Register reported that the campaign infected more than 3,000 servers since April and used compromised systems to mine cryptocurrency and expand its botnet. | The Register | Attributed |
| The Register reported that Black Lotus Labs called this its first observed real-world case of adversarial poetry. | The Register | Attributed |
| The Register reported that the poem contained no links, downloadable files or easily flagged encrypted text. | The Register | Attributed |
| The Register reported that PoeLLM primarily affected vulnerable internet-facing LiteLLM and Ollama systems, with hundreds of victims running Gotenberg and Gitea. | The Register | Attributed |
Could not verify
- Whether the campaign has been exploited by other actors is not established.
- How many organizations or individuals were behind the campaign is not established.
- Whether the reported Italian-speaking actor is the malware developer is not established.
- Whether the related vulnerabilities were exploited in every reported infection is not established.



