Black Lotus Labs, the threat research team at Lumen, says a malware family it calls PoeLLM has compromised more than 3,400 servers, most of them internet-facing AI and open-source services, and finds its command server by reading a poem posted on GitHub.
What Lumen reported
Lumen published its research under the name “Canto Incognito.” According to the post, Black Lotus Labs has tracked the campaign since April 2026. The malware deploys the XMRig and Iron cryptocurrency miners and connects victims to Kryptex mining infrastructure, which led the team to assess the operator as financially motivated. Lumen links the activity to an Italian-speaking threat actor.
Most victims run vulnerable versions of open-source AI and LLM services. Lumen names LiteLLM and Ollama, and says the malware also reached hundreds of servers running the PDF converter Gotenberg and the development toolkit Gitea. It adds that other commercial software may have been targeted, including Ivanti Sentry. The victims are mostly in the United States and Western Europe.
Lumen says the campaign peaked in mid-June with nearly 800 servers active per day. It reports that Black Lotus Labs has blocked all traffic to and from the PoeLLM command-and-control servers, and that Lumen Defender customers have been protected since the team found the malware.
How the poem works
The unusual part is the control channel. Lumen says the malware does not carry a fixed server address. It reads a two-stanza poem in a file on a GitHub repository forked from the nodejs.org website source, then turns four words from the poem into the numbers of an IPv4 address through a dictionary built into the malware. When the operator wants infected hosts to talk to a new server, they change the keywords in the poem and the victims work out the new address on their own.
Black Lotus Labs counts 11 changes to the poem since the first commit on April 13, 2026, and 12 command server addresses in total, three of which were still active at publication. For defenders, a fixed blocklist ages quickly against this design. Lumen publishes its indicators and says it updates them on GitHub.
Infected servers become scanners
Lumen says compromised hosts do more than mine. After infection, several victim servers were put to work scanning for other vulnerable systems and acting as exploit servers, which widens the botnet without the operator’s own infrastructure doing the work. The team also saw pools of victims aimed at SSH ports and other login portals, which it reads as possible early experimentation with distributed brute-force attacks. It rates that capability’s maturity as uncertain.
The team first found the infrastructure while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. In early June, a compromised Ivanti Sentry device contacted a dedicated server and then began scanning for other vulnerable devices. Lumen also says the operator appears to have used routers with vulnerable administration interfaces to supply part of the command infrastructure. That repeats a pattern CyberTech has covered before, in which attackers target the consoles that secure the network and use edge devices as stepping stones.
Why exposed AI services are the draw
Lumen’s argument is that AI infrastructure is attractive for two reasons. These services can hold useful data, and they often run on powerful GPU hardware that suits cryptocurrency mining. The post says enterprise attack surfaces are growing quickly as AI infrastructure grows, and that new tools “often go unmonitored for vulnerabilities despite access to powerful compute and valuable enterprise data.”
The research also points to guidance that was already in place. When Black Lotus Labs enriched the victim IP addresses, most were running AI tools such as LiteLLM and Ollama, or other open-source platforms with known vulnerabilities. The installation guide for Gotenberg carries an explicit warning not to expose the service to the internet, and Lumen reproduces it in the post. The hosts that were infected were reachable from outside anyway.
The command channel has a counterpart in other recent malware. CyberTech reported on Fortinet’s analysis of ClingSTUN, a Linux backdoor that uses public STUN servers, and the pattern is the same: the malware borrows a legitimate public service, so blocking a single address does not cut the operator off.
What it means for the security leader
Three points follow from the Lumen findings, and the first two come straight from its recommendations. Inventory every AI and LLM service that answers on an external interface, including ones a developer stood up for a pilot. Audit external exposure after installing any new open-source tool, and restrict the ports it needs to the narrowest set of sources. Include AI infrastructure in attack surface management and in the normal patch and update cycle.
The third point is ours. Treat a model-serving host as an edge system. It runs internet-reachable software, holds credentials and API tokens for upstream models, and sits on expensive compute that an attacker can monetize quickly. It deserves the monitoring a VPN gateway or a mail server gets, including alerts on unexpected GPU load.
What defenders should do now
- Search network and firewall logs for connections to the command servers and mining endpoints in Lumen’s indicator list, and compare against the GitHub list it keeps current.
- Find every LiteLLM, Ollama, Gotenberg and Gitea instance reachable from outside, and move each behind a firewall, VPN or SASE service. Lumen recommends this as the way to stop scanners from treating the servers as targets.
- Patch internet-facing AI and development tools on the same schedule as other edge software, and alert on unexplained GPU load or outbound connections to mining pools.
- Apply routine router and firewall hygiene, including regular reboots and timely updates, since Lumen saw vulnerable routers reused as command infrastructure.
Lumen’s own assessment is that the security of these systems “cannot take a backseat to convenience.” The post describes one operator and one campaign, and it does not claim to cover every group scanning for exposed AI services. Defenders can still act on it today, because the entry point it describes is a service that was open to the internet.
Source: Lumen Black Lotus Labs, “Canto incognito: tracking the PoeLLM malware”