GBHackers

PoeLLM Malware Hijacks 3,400+ Servers for Crypto Mining and Botnet Expansion


A cryptocurrency mining campaign dubbed PoeLLM has compromised more than 3,400 servers by targeting exposed AI infrastructure and other internet-facing applications.

Active since April 2026, the operation combines vulnerability exploitation, cryptocurrency miners and an unusual command-and-control mechanism that derives server addresses from a poem hosted on GitHub.

Victims predominantly run LiteLLM, Ollama, Gotenberg and Gitea, with possible targeting of Ivanti Sentry. Most affected systems are concentrated in the United States and Western Europe.

The research’s headline findings report peak activity exceeding 800 active servers daily, while earlier sections describe approximately 2,200 affected servers, indicating different reporting snapshots.

PoeLLM retrieves its control instructions from “On the Nature of Connection,” a poem embedded in a file named dash.css within a fork of the Node.js website repository.

Researchers found no apparent connection between the malware and legitimate Node.js software.

The malware extracts four words or phrases using fixed textual markers, then maps them through a hardcoded dictionary to numerical values.

These values become the four octets of an IPv4 address identifying the current command-and-control server.

By modifying selected words, the operator can redirect infected machines without replacing their malware. Researchers observed 11 poem updates following the repository’s initial April 13 commit.

 PoeLLM victim count, April – September 2026 (Source : Black Lotus Labs).

The decoding pattern remained unchanged, allowing investigators to reconstruct infrastructure transitions.

Black Lotus Labs said in a report shared with GBhackers, while investigating a compromised Ivanti Sentry system that contacted 5.78.73[.]122 and subsequently began scanning other devices.

Further telemetry exposed widespread scanning against ports 3000 and 4000, associated with Gotenberg and LiteLLM deployments.

PoeLLM Malware

Successful attacks instructed targets to retrieve payloads from command servers on port 81. Infected systems subsequently communicated over ports 3778, 5001, 5002 or 9999.

One analyzed sample referenced LiteLLM’s /mcp-rest/test/connection endpoint, consistent with CVE-2026-42271.

The vulnerability affects versions 1.74.2 through versions preceding 1.83.7 and permits authenticated users, including low-privilege API-key holders, to execute commands through supplied MCP configurations.


Canto Incognito campaign overview (Source : Black Lotus Labs).
Canto Incognito campaign overview (Source : Black Lotus Labs).

Version 1.83.7 fixes the issue. Importantly, this is authenticated command execution, not an unauthenticated flaw.

The ELF payload, named libgcrypt, incorporates remote-shell capabilities, HTTP/S scanning, exploit deployment, and XMRig and Iron miners.

Victims contacted Kryptex mining infrastructure, including 5.180.174[.]162:8029 and 46.21.245[.]211:7029.

The initial C2 decoded from the poem was 191.37.28[.]160 and appears to have been used to test the infection process.

Compromised machines also became scanning and exploitation workers, distributing the campaign’s expansion across victim infrastructure.

initial C2 contact with Italian language comments (Source : Black Lotus Labs).
initial C2 contact with Italian language comments (Source : Black Lotus Labs).

Recent traffic toward SSH services and login portals suggests experimentation with distributed brute-force attacks, although researchers considered that capability immature.

Several decoded command servers exposed vulnerable Boa router administration interfaces, suggesting the operator reused compromised network devices.

Researchers did not establish direct exploitation evidence for the vulnerabilities identified on the initial Brazilian router.

Italian-language comments and infrastructure connections support an Italian-speaking operator assessment, not a confirmed nationality.

Researchers separately assessed an Italy-hosted server as a probable administrative interface with moderate confidence.

Lumen says it blocked traffic to and from identified PoeLLM command servers. Defenders should correlate the reported download paths, mining connections and scanning activity with exposed application inventories.

Gotenberg’s installation guidance explicitly warns against public internet exposure and recommends keeping the service behind a firewall.

The documentation also demonstrates localhost-only port binding, directly addressing the deployment exposure exploited by campaigns targeting publicly reachable conversion services.

IOCs

IP AddressStart DateEnd Date
191.37.28.160April 13, 2026May 16, 2026
89.39.253.46April 14, 2026June 24, 2026
120.224.114.212May 9, 2026September 8, 2026
5.78.73.122June 8, 2026August 22, 2026
15.204.178.28June 14, 2026August 17, 2026
92.119.165.74July 1, 2026July 23, 2026

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.



Source link