PoeLLM botnet hides C2 address in a GitHub poem
A cryptomining botnet that breaks into exposed AI servers locates its command and control (C2) infrastructure by reading a poem hosted on GitHub, according to researchers at Black Lotus Labs.
The researchers named the malware PoeLLM. It has compromised more than 3,400 servers since April 2026, most of them in the US and Western Europe. Black Lotus Labs tracks the activity as Canto Incognito. It attributes the campaign to an Italian-speaking threat actor who appears to be motivated by money.
AI services in the crosshairs
Most infected machines run vulnerable versions of open-source AI and large language model (LLM) services such as LiteLLM and Ollama. The malware also hit hundreds of servers running Gotenberg, an open-source PDF converter, and Gitea, a software development toolkit.
The researchers say attackers have two reasons to target servers running AI/LLM implementations. These servers can be a source of intelligence. They are also self-hosted services that are exposed to the internet and have known vulnerabilities.
An Ivanti lead
Black Lotus Labs found PoeLLM while investigating CVE-2026-10520, a vulnerability in Ivanti Sentry. In early June 2026, a compromised Ivanti Sentry device contacted a dedicated server at 5.78.73[.]122. Shortly afterwards it began scanning for other vulnerable systems.
The team's telemetry showed that the first GitHub commit containing the poem was made on April 13. Early traffic from the first known C2 suggested the operator briefly tested infections and payload downloads.
From May onward, the attacker scanned the internet mainly for ports 3000 and 4000, the default ports for Gotenberg and LiteLLM. When a scan found a vulnerable server, an exploit server sent it a crafted POST request that told it to download a file from the C2. In the sample the researchers analyzed, the targeted LiteLLM endpoint (/mcp-rest/test/connection) is referenced in CVE-2026-42271, a command injection flaw in LiteLLM.
Four words, one IP address
The poem is titled "On the Nature of Connection." It sits in a file named dash.css in a GitHub repository created by a user called "ejejejdfbbebe." The repository is a fork of the nodejs.org website source code, although the malware has no link to Node.js.
PoeLLM takes four words from fixed positions in the poem. It looks up each word in a dictionary hard-coded into the malware, which maps it to a number. The four numbers make up the IPv4 address of the current C2 server. In one earlier version of the poem, the words "driver," "diode," "decryption" and "string" translated to 92, 119, 165 and 74. That sent the bots to 92.119.165.74.
To move the botnet to a new server, the operator only has to swap those four words in the repository. Infected machines then work out the new address on their own. The poem has been edited 11 times since the first commit, and each edit redirected victims to a different server.
"At the time of writing, the malware creator has not changed the pattern used in deciphering the poem. Only the keywords have changed over the 11 iterations we have observed," the researchers noted.
Mining, then spreading
Once installed, PoeLLM runs the XMRig and Iron cryptocurrency miners and connects victims to the Russian Kryptex mining pool. It also includes a remote shell, HTTP/S scanning and exploit deployment features. The botnet grows by putting infected servers to work scanning for and exploiting new targets.
More recently, groups of bots have started targeting SSH ports and other login portals. The researchers say this suggests the operator may be experimenting with distributed brute-force attacks. That capability appears to be at an early stage of development.
Black Lotus Labs says it has blocked traffic to and from the PoeLLM C2 servers and will keep monitoring for new traffic.
"Delays in updating internet-facing AI and enterprise tools enable highly trusted access," the researchers wrote. They added that AI tools need to be included in attack surface management and patch cycles. In their view, this protects against token abuse and cryptomining, and more critically against data loss, LLM jacking and lateral movement.
Our Take
The poem trick is clever, but the root problem is familiar. Organizations are spinning up self-hosted AI services faster than they patch them. PoeLLM did not need a zero-day. It scanned default ports and exploited known flaws in tools like LiteLLM. This fits a wider pattern of AI infrastructure becoming an attack surface in its own right, from flaws in AI gateway components to survey findings that attacks on AI systems are among companies' biggest readiness gaps.
Hiding C2 data on GitHub also shows how attackers rely on trusted platforms that defenders rarely block. Recent campaigns such as FakeGit's malicious repositories point the same way. Because the decoding pattern has stayed the same across 11 edits, defenders currently have a reliable way to track the operator. It is worth watching whether the operator changes the scheme now that it is public, and whether the early brute-force activity grows into something more serious. Teams running LiteLLM, Ollama, Gotenberg or Gitea should check their exposure and patch levels now.
