AI Weekly Malaysia

Back to items Summaries

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

ID
32838
Status
summarized
Published
07 Oct 2026, 11:33 PM
Fetched
08 Oct 2026, 12:50 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/poellm-malware-infects-3400-servers-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
08 Oct 2026, 12:51 AM
Tags
Audience
developersai_ml_learnersai_agent_userssaas_founders

What happened

Lumen Black Lotus Labs detailed a campaign it calls Canto Incognito, where malware codenamed PoeLLM has infected more than 3,400 internet-facing servers since April 2026 to install XMRig and Iron cryptocurrency miners and connect victims to the Kryptex mining service. Targets are mostly AI/LLM infrastructure and dev tooling — LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances — and the C2 address is hidden inside a poem hosted in a GitHub repository (github.com/ejejejdfbbebe, first commit April 13, 2026), with a few words swapped each time a new C2 is set up. Peak activity was mid-June 2026 at nearly 2,200 affected servers with about 800 active per day, concentrated in the U.S. and Western Europe; compromised hosts are reused as scanners and exploit servers, and recent traffic suggests experimentation with distributed SSH brute-force.

Why it matters

If you self-host LiteLLM, Gotenberg, Gitea, or similar tooling on a public IP, this is the concrete failure mode: your GPU/CPU gets rented out for someone else's Monero mining and your box becomes a scanner for the next victim. Decide this week whether your LLM gateway is reachable from the open internet at all, and whether it sits behind auth, a VPN, or an allowlist — the article shows exploitation of exposed deployments, not a patchable CVE. The poem-based C2 also means static blocklists of C2 domains will not help; detection has to look at outbound mining-pool traffic and unexpected outbound connections.

Discussion angle

Do a live check: who in the room has a LiteLLM or similar LLM proxy bound to 0.0.0.0 on a public IP, and what would actually stop a miner from being installed there — network exposure, auth, or egress filtering? The poem-C2 detail is a good hook for why domain blocklists alone fail.

Top