CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLENATOB2threat

PoeLLM: a cryptomining botnet that reads its C2 address out of a GitHub poem compromises exposed LiteLLM, Ollama, Gotenberg and Gitea servers and turns them into scanners

Lumen: a botnet takes its C2 address from a GitHub poem and spreads through exposed AI and developer servers

Analysis

Lumen's Black Lotus Labs says PoeLLM has been active since at least April 2026, deploys XMRig and Iron cryptocurrency miners that connect to a Kryptex mining pool, and is deployed through vulnerability exploitation of publicly exposed services, mainly LiteLLM and Ollama and, in the hundreds, the Gotenberg PDF converter and Gitea, with other products such as Ivanti Sentry possibly targeted (Lumen, 2026-10-07). It counts more than 3,400 impacted servers, a figure it raised after first circulating the report (BleepingComputer, 2026-10-07), predominantly in the United States and Western Europe, and assesses that PoeLLM is associated with an Italian-speaking threat actor (Lumen, 2026-10-07).

The command channel is the unusual part: the malware derives its current C2 server from keywords in a poem hosted in a GitHub repository, so the operator rotates servers by editing the poem, which Lumen counts 11 edits of since the first commit on 2026-04-13 (Lumen, 2026-10-07). Several C2 servers were routers with exposed administration pages, which Lumen reads as the operator repurposing compromised routers (Lumen, 2026-10-07). Infected servers become scanners and exploit launchers that sweep ports 3000 and 4000, the primary ports of Gotenberg and LiteLLM, and send a crafted POST that makes the target fetch a payload from the C2; the payload is a single ELF binary that bundles a remote shell, the miners, HTTP and HTTPS scanning and exploit deployment, and beacons back to the C2 (Lumen, 2026-10-07). For LiteLLM, Lumen says the endpoint /mcp-rest/test/connection, which the CVE-2026-42271 command injection references, was likely the exploitation path (Lumen, 2026-10-07), and BleepingComputer adds that Horizon3 showed it can be chained with CVE-2026-48710 for unauthenticated remote code execution (BleepingComputer, 2026-10-07). Lumen met the infrastructure while investigating the Ivanti Sentry flaw CVE-2026-10520, when a compromised Sentry victim contacted a PoeLLM C2 and began scanning for other vulnerable devices; it states no further link between that flaw and the botnet (Lumen, 2026-10-07).

Cited evidence

The malware derives its current C2 server from keywords in a poem hosted in a GitHub repository.

We assess that PoeLLM is associated with an Italian-speaking threat actor and is deployed through vulnerability exploitation of publicly exposed services.

Lumen Black Lotus Labs 2026-10-07

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.