Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cryptomining malware used poetry to infect more than 3,400 servers, researchers say

Lumen's Black Lotus Labs says PoeLLM malware has hit more than 3,400 servers, most of them exposed AI tools like LiteLLM and Ollama.

Cryptomining malware used poetry to infect more than 3,400 servers, researchers say

Over 3,400 servers were infected by cryptomining malware called PoeLLM as part of a campaign dubbed Canto Incognito, according to Black Lotus Labs. The malware's command-and-control (C2) mechanism utilized a poem with address encoding on GitHub, modified 11 times thus far, to direct affected hosts to new C2 servers. Most of the infected servers were running vulnerable versions of open-source AI/LLM services like LiteLLM and Ollama, despite a fix released in April.

The malware's payload consisted of XMRig and Iron miners, linked to Kryptex mining infrastructure, turning infected servers into scanners and exploit servers. The majority of the first 900 victims had contacted a Russian crypto mining service endpoint, suggesting a financially motivated attack. AI infrastructure is becoming an attractive target due to the potential value of data and hardware access, particularly GPUs.

To combat the malware, users should block traffic to and from the PoeLLM C2 servers and patch all vulnerable network devices. The primary targets included LiteLLM, a proxy server connecting to LLM APIs, Gotenberg, a Docker-based API for PDF conversion, Ollama, which enables running open-weight models, and Gitea, a self-hosted Git platform.

Ivanti Sentry, an enterprise gateway appliance, may have also been targeted. While the malware's methodology uses poetry for obfuscation, it is not an AI jailbreak or adversarial poetry. The malware was deployed through vulnerability exploitation of exposed services, with a crafted POST request likely being the exploitation path for LiteLLM.

Users can check for indicators of compromise on Lumen's GitHub page and follow individual advisories for the vulnerable products. The campaign continues to infect new victims, with Lumen stating that enterprise attack surfaces are rapidly expanding as AI infrastructure grows.

Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at tomshardware.com →

More in Tech

A refactor without tests is a rewrite

Originally published on hayatibis.dev , where the figures move and the toys are interactive. “I’m refactoring it” is one of the most stretched sentences in software.

  • Refactoring without tests can become a rewrite
  • Tests capture current code behavior, identify deviations
  • Small, test-checked steps mitigate rewrite risk

What a Horror Movie Page Taught Me About Building Better Content Experiences

When building a movie discovery website, it's easy to focus entirely on movie titles, posters and release dates. But a good movie page needs to do more than display information.

  • Hero section should prioritize movie title, release year, and genre
  • Clear content hierarchy improves user experience
  • Promotional material should follow essential information

More from Sunday 11 October →