Lumen Black Lotus Labs: PoeLLM cryptomining botnet reads its command server address from a poem on GitHub and spreads through exposed LiteLLM, Ollama, Gotenberg and Gitea servers; Ivanti Sentry also hit
Lumen's Black Lotus Labs published research on 7 October 2026 into PoeLLM, Linux malware (an ELF file named libgcrypt) behind a cryptomining and exploit-scanning campaign aimed mainly at self-hosted AI infrastructure. Instead of a hard-coded server, each infected host reads a poem titled "On the Nature of Connection" from a dash.css file in a GitHub repository dressed up as a Node.js fork, picks out four words or phrases and turns them into an IPv4 address with a built-in dictionary; the operator moves command-and-control by editing the poem, which has been changed 11 times since the first commit on 13 April 2026. Black Lotus Labs first found the infrastructure while investigating Ivanti Sentry CVE-2026-10520, when a compromised Sentry appliance contacted 5.78.73[.]122 in early June and began scanning. Most victims run vulnerable, internet-exposed LiteLLM or Ollama, and hundreds run the Gotenberg PDF converter or Gitea; infected servers scan ports 3000 and 4000 (Gotenberg and LiteLLM) and try LiteLLM CVE-2026-42271, which Horizon3.ai showed can be chained with CVE-2026-48710 for unauthenticated code execution. The implant includes a remote shell, XMRig and Iron miners tied to the Russian mining service Kryptex, HTTP/S scanning and exploit delivery, and some command servers sat on compromised home routers. Lumen counted almost 2,200 affected servers at the mid-June peak with nearly 800 active a day, mostly in the US and Western Europe; BleepingComputer and The Hacker News report the live count has since passed 3,400. Lumen assesses with moderate confidence the operator speaks Italian, and says it has blocked all traffic to the known command servers. Primary: Lumen Black Lotus Labs; wires: BleepingComputer and The Hacker News (7 Oct).
- Product
- Internet-exposed LiteLLM, Ollama, Gotenberg and Gitea servers; Ivanti Sentry (CVE-2026-10520)
- Versions
- n/a — malware campaign exploiting known flaws in unpatched, exposed services (LiteLLM CVE-2026-42271 / CVE-2026-48710 chain named)
- Exploited in Australia?
- unknown
- Patch to
- Patch LiteLLM, Ollama, Gitea and Ivanti Sentry, and take Gotenberg off the internet (its own install guide says not to expose it). Put AI gateways and model servers behind a VPN or allow-list, alert on GPU or CPU saturation from unknown processes and on a file named libgcrypt outside system library paths, and hunt for connections to 5.78.73[.]122, 120.224.114[.]212 and Kryptex pool 5.180.174[.]162 plus the rest of Lumen's indicators.
Primary: Lumen Black Lotus Labs — Canto Incognito: tracking the PoeLLM malware (7 Oct 2026) · Vendor: Horizon3.ai — LiteLLM CVE-2026-42271 chained with CVE-2026-48710 for unauthenticated RCE · CVE: CVE-2026-10520, CVE-2026-42271, CVE-2026-48710 · BleepingComputer — PoeLLM malware infects exposed AI servers in cryptomining attacks (7 Oct 2026)
