Signal

PoeLLM malware campaign targets exposed AI infrastructure

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-10-07 15:00 UTCUpdated 2026-10-07 16:01 UTC
rss
malwarebotnetai_securitycryptominingcommand_and_controlthreat_actor
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
The Hacker News report on the PoeLLM botnet
thehackernews.com · thehackernews.com · 2026-10-07 15:33 UTC
Overview

PoeLLM is described as malware targeting exposed AI and LLM infrastructure, using a poem posted to GitHub to derive a command-and-control address. Reports say the campaign has compromised more than 3,400 servers since April, deploying cryptocurrency miners and expanding a botnet.

Entities
Lumen TechnologiesBlack Lotus LabsPoeLLMCanto IncognitoRyan English
Why now
  • Reports published within the past 24 hours put the campaign’s reported scale above 3,400 compromised servers.
  • Researchers have highlighted the use of a poem as an operational mechanism in a real-world malware campaign.
Why it matters
  • AI and LLM infrastructure is being used as a target for botnet expansion and cryptomining.
  • The campaign hides command-and-control data in content that can appear benign to observers.
Evidence assessment
Recurring claims
  • PoeLLM has compromised more than 3,400 servers since April while targeting exposed AI or LLM infrastructure.
  • The malware uses four words extracted from a GitHub-hosted poem to derive a command-and-control server address.
  • The campaign deploys cryptocurrency miners and uses compromised systems to expand its botnet.
How sources frame it
  • CyberScoop: neutral
  • The Register: neutral
  • The Hacker News: neutral
Three reports describe the same malware campaign targeting exposed AI infrastructure.
All evidence
All evidence
CyberScoop report on PoeLLM and Black Lotus Labs findings
cyberscoop.com · cyberscoop.com · 2026-10-07 15:00 UTC
The Register report on PoeLLM infections and cryptomining
theregister.com · theregister.com · 2026-10-07 16:01 UTC
The Hacker News report on the PoeLLM botnet
thehackernews.com · thehackernews.com · 2026-10-07 15:33 UTC
Show filters & breakdown
Evidence items loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 3