Security3 publishersReports disagree2 min readPublished
PoeLLM botnet has turned more than 2,100 exposed servers into miners and scanners
Lumen's Black Lotus Labs says the PoeLLM cryptomining botnet has compromised more than 2,100 servers, many running exposed LiteLLM or Ollama. Each host it takes then mines and scans for the next, so an AI server left open to the internet is attack surface to lock down.
The Watch · Security desk

What happened
- The botnet has run since at least April, and its operator has stood up at least 11 command-and-control servers as activity grew.
- Infected servers scan ports 3000 and 4000, associated with Gotenberg and LiteLLM, and try to exploit CVE-2026-42271 in LiteLLM.
- Horizon.ai researchers confirmed CVE-2026-42271 can be chained with CVE-2026-48710 to get remote code execution without authentication.
- The malware decodes its command server's IP address from words in a poem hosted on GitHub, and the operator has edited the poem 11 times to move it.
- Black Lotus Labs made no confident attribution but assesses with moderate confidence that the operator is Italian.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Patch queues that filed CVE-2026-42271 as an authenticated bug need to move it up, because an exposed LiteLLM proxy hit with the full chain requires no credentials.
- exposure Each hijacked server becomes the operator's launch point, so the scans and exploit attempts hitting other networks arrive from the victim's own address.
- constraint Blocking one C2 address holds only until the operator next edits the poem, because the address lives in a GitHub file the operator can change at will.
- cost The owner of a hijacked GPU host pays for the compute and power behind mining traffic sent to Kryptex.
CVE-2026-42271 sits in LiteLLM's MCP server test endpoints [15]. It was originally disclosed as requiring authentication and scored high severity [15]. BleepingComputer's account of the research does not name the flaw used against the Ollama hosts among the victims [2].
On any one day the botnet is smaller than its running total: the busiest day, 800 active infections, is at most about 38 percent of the more than 2,100 servers compromised [6][20].
Each implant carries a remote shell, the XMRig and Iron miners, HTTP/S scanning and an exploit deployer [8]. Victims communicate with Kryptex, a Russian crypto-mining service [10]. The victim list runs past AI tooling to the Gotenberg PDF converter and the Gitea development toolkit, with signs of Ivanti Sentry targeting as well [2]. The operation targeted systems across the United States and Western Europe [9].
The researchers give a plain reason for the AI focus. LLM deployments are often poorly configured and exposed online, and they typically run on GPU clusters suited to cryptomining [12].
The command lookup is the uncommon part [3]. The implant, an ELF file named libgcrypt, reads four words or phrases from a poem titled "On the Nature of Connection" inside a dash.css file, in a GitHub repository that appears to fork Node.js [4]. A hard-coded dictionary maps the words to numbers that form the C2's IPv4 address [5]. Several C2 servers had vulnerable router administration interfaces. Lumen's researchers take that as a sign the operator reused compromised routers [17].
The Italian assessment rests on comments in the malware and an Italy-based server hosting the administrative interface [13]. The indicators of compromise are public, and Black Lotus Labs advises checking network monitoring logs for connections to them [18].
Its other advice is to apply the latest updates, reduce public internet exposure and restrict external access to trusted IPs [18]. As described, the spread step needs LiteLLM and Gotenberg ports reachable from outside [11]. Restricting those ports to trusted addresses closes that path without waiting on a patch [11][18].
What to watch
- Another edit to the "On the Nature of Connection" poem, which Black Lotus Labs suspects is coming, would move the C2 again and confirm the operator is still maintaining the botnet.
- Whether PoeLLM's exploit module adds CVE-2026-48710, the second half of Horizon.ai's chain, to its LiteLLM attempts.
- New exploits in the kit aimed at Ollama or Gitea, the other tools common among victims.