// 1 CRITICAL · 2 ZERO-DAY · 6 CVE · 3 EXPLOIT IN THE LAST 24H→
The PoeLLM botnet has compromised over 3,400 AI servers by exploiting CVE-2026-42271. Command-and-control addresses are concealed in a poem hosted on GitHub, enabling infrastructure rotation without payload updates.

The PoeLLM malware has compromised more than 3,400 internet-exposed AI servers since April 2026, building a cryptomining botnet that evades detection by hiding command-and-control server addresses in a poem hosted on GitHub. The campaign, discovered by Lumen Black Lotus Labs during a parallel investigation into an Ivanti Sentry vulnerability in June, marks an evolution in malicious infrastructure resilience: the C2 address is dynamic, reconstructed from literary text via a hard-coded dictionary in the payload.

Key Takeaways
  • The PoeLLM malware, an ELF file named libgcrypt, has compromised over 3,400 exposed AI servers since April 2026, according to Black Lotus Labs via CyberScoop.
  • C2 server IPv4 addresses are generated dynamically by extracting four words from a GitHub poem and mapping them through a hard-coded dictionary in the malware.
  • The operator has modified the poem at least 11 times to rotate infrastructure without updating the deployed payload.
  • Black Lotus Labs attributes the operator to an Italian-speaking actor with moderate confidence, based on code comments and servers located in Italy.

How the C2 Linguistic Steganography Works

The core mechanism of PoeLLM is the reconstruction of the command-and-control server address through a linguistic decoding process. The malware embeds a hard-coded dictionary mapping individual words to numbers: for example, "driver" maps to 92, "diode" to 119, "decryption" to 165, and "string" to 74. These four numbers, combined, form a complete IPv4 address.

To obtain the correct words, the malware retrieves a poem titled "On the Nature of Connection" hosted in the dash.css file of a GitHub repository bearing the hallmarks of a Node.js fork. The repository received its first commit on April 13, 2026, according to The Hacker News. The malware extracts four specific words from the poetic text based on their position relative to "fixed text anchors" — literary segments serving as stable positional references.

This architecture grants the operator unprecedented infrastructure rotation capability. Each modification of the poetic text — the operator has altered the poem at least 11 times, with at least one additional suspicious change noted by BleepingComputer — automatically generates a new C2 address on already compromised systems. No malware redeployment, payload updates, or new communication channels are required. The GitHub file appears entirely as an innocuous literary text: devoid of links, executables, or ciphertext easily flagged even by advanced detection models.

"To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models" — Ryan English, Black Lotus Labs

Mass Infection of AI Servers and Payload Capabilities

The compromised servers are predominantly publicly exposed AI infrastructure, often deployed as proof-of-concepts turned production services without adequate hardening. The malware scans ports 3000 and 4000, associated with Gotenberg and LiteLLM respectively, and attempts to exploit CVE-2026-42271 — an OS command injection vulnerability rated CVSS 8.8 per the Red Hat classification reported by Windows Forum.

The ELF payload libgcrypt integrates multiple capabilities: remote shell, XMRig and Iron miners, HTTP/S scanning, and exploit deployment. Victims communicate with Kryptex, a Russian-origin cryptomining service. A mid-June activity peak involved nearly 2,200 affected servers, with approximately 800 systems active in a single day according to Black Lotus Labs data via BleepingComputer. CyberScoop reports a cumulative total of over 3,400 compromised servers, indicating continued proliferation over the months.

CVE-2026-42271 impacts LiteLLM MCP server test endpoints. Originally disclosed as requiring authentication with high severity, it can be chained with CVE-2026-48710 to achieve unauthenticated RCE, according to Horizon3.ai. The exploit chain has not been independently verified in the available editorial dossier.

Why the C2 Mechanism Defeats Traditional Defenses

The resilience of the poem-GitHub C2 vector lies in its infrastructural invisibility. The IP address never traverses external netflow in cleartext: it is reconstructed locally by the malware through operations on legitimate public text. Ryan English of Black Lotus Labs emphasizes that "the IP address used for C2 communications is invisible outside the victim's netflow." This renders static IP blocks, intelligence blacklists, and signature-based analysis of command domains ineffective.

The architecture also resists takedowns. Removing a single C2 server does not disrupt the network: the operator simply modifies the poem, activating a new endpoint. At least 11 C2 servers have been activated during the campaign. Several featured vulnerable router administration interfaces, suggesting reuse of compromised devices as hosting platforms.

For perimeter defenses, egress anomaly detection and behavioral monitoring become critical: no static indicator of compromise exists to block, only a pattern of repeated access to a specific GitHub repository followed by outbound connections to dynamically reconstructed addresses.

Attribution to an Italian Actor and Dossier Limitations

Black Lotus Labs attributes the operator to an Italian-speaking actor with moderate confidence. The assessment rests on two artifacts: Italian-language comments in the malware source code, and test and command servers located in Italy. The attribution does not reach certainty: no documented infrastructure overlaps link the actor to known threat groups, and the exact number of individuals involved in the operation remains unknown.

The dossier does not specify the full nature of data exposed on compromised servers, nor the extent of profit generated via Kryptex. The CVE-2026-42271 + CVE-2026-48710 chain for unauthenticated RCE is not independently confirmed. The geographic distribution of victims outside the United States and Western Europe is not quantified, and the current status of the GitHub repository — active or removed — is not documented in available sources.

Immediate Actions

Priority actions derive directly from the mechanisms documented by the source:

  • Verify public exposure of LiteLLM, Ollama, Gotenberg, and Gitea services: the malware specifically scans ports 3000 and 4000 and attempts exploitation of CVE-2026-42271.
  • Analyze outbound traffic to specific GitHub repositories, particularly repeated access to seemingly innocuous text files that could serve as linguistic steganography vehicles.
  • Monitor for ELF processes named libgcrypt in Linux environments, verifying they correspond to the legitimate library of the same name.
  • Review AI infrastructure segmentation: compromised servers serve as proxies for further attacks, credential theft, and token abuse, according to Black Lotus Labs.

The risk of escalation warrants measured consideration. Ryan English warns the actor has "effectively created a private army of AI-enabled proxies that will continue to multiply and provide additional vectors for attack, credential theft, token abuse, and more." The technical capability exists; its systematic activation is not documented in sources as an ongoing event.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. cyberscoop.com
  2. bleepingcomputer.com
  3. thehackernews.com
  4. windowsforum.com
  5. deals.bleepingcomputer.com