
PoeLLM Botnet Hits 3400 Servers via Exposed LiteLLM and Gitea Instances Since April 2026
PoeLLM has enlisted more than 3400 AI servers into a cryptomining botnet since April 2026 by encoding C2 addresses in a mutable GitHub poem. Moderate-confidence Italian attribution rests on language artifacts and netflow; no independent confirmation exists. The campaign recycles victims as scanners, exposing a widening gap between AI infrastructure deployment and defensive controls.
The campaign targets enterprise deployments of LiteLLM, Gotenberg, Gitea, and Ivanti Sentry by exploiting exposed endpoints. Compromised hosts receive HTTP POST instructions to pull payloads from C2 servers whose addresses are encoded in a GitHub-hosted poem that changes per campaign iteration. Peak activity reached nearly 2200 victims in mid-June with roughly 800 daily active nodes concentrated in the US and Western Europe. Infected systems are then tasked with scanning for additional SSH and login portals. Lumen Black Lotus Labs traced the activity through netflow records and Italian-language strings in artifacts, assigning moderate confidence to an Italian-speaking operator. The first GitHub commit occurred 13 April 2026 under the repository ejejejdfbbebe. No independent technical attribution beyond these indicators has surfaced, and the group has not been linked to prior named campaigns. The use of AI workloads for mining highlights a shift toward high-compute targets rather than traditional IoT or web servers. The operation demonstrates a closed-loop recruitment model where victims become both miners and exploit delivery nodes. Recent traffic toward brute-force attempts suggests the actors are testing distributed credential attacks, though maturity remains unclear. Procurement records show continued growth in exposed LLM inference endpoints, increasing the available attack surface without corresponding hardening mandates.
Lumen Black Lotus Labs: Active daily victims will surpass 1200 within 90 days if no major infrastructure takedown occurs.
Sources (2)
- [1]Primary Source(https://thehackernews.com/2026/10/poellm-malware-infects-3400-servers-to.html)
- [2]Supporting Source(https://blog.lumen.com/black-lotus-labs-canto-incognito-report)