05
PoeLLM botnet compromises more than 3,400 servers, hiding command servers in a GitHub poem
Black Lotus Labs says the PoeLLM malware has infected more than 3,400 servers since April 2026, mostly in the US and Western Europe, by exploiting exposed services including LiteLLM, Ollama, Gotenberg and Gitea. The malware derives its command-and-control address from words in a poem stored in a GitHub repository, and infected systems mine cryptocurrency and scan for new victims. Researchers say the operator may also be experimenting with distributed brute-force attacks.
What changed Beyond scanning for vulnerable services, groups of bots have recently begun targeting SSH and other login portals. Researchers interpret this as possible early-stage distributed brute-force experimentation, not an established capability.
Why it matters Compromised server operators face both unauthorized mining and reuse of their infrastructure to attack other systems; removing miners alone would not address the malware’s remote shell and exploitation capabilities.
What to watch next Black Lotus Labs says it will continue monitoring for new traffic after blocking communications with known PoeLLM command servers.
HelpNet Security ↗