Indicators of compromise · XMRIG — 1 shown
0ad68d5804804c25a6f6f3d87cc3a3886583f69b7115ba01ab7c6dd96a186404
Defanged third-party indicators (abuse.ch). The defanging is deliberate: never click, resolve or fetch these values. An indicator corroborates a report — it never proves one, and its presence here does not mean this story's hosts are listed.
Lumen's Black Lotus Labs reported that PoeLLM, active since at least April, has compromised more than 3,400 servers — peaking at 800 active in a single day — largely in the US and Western Europe, with victims running exposed AI services such as LiteLLM and Ollama, plus the Gotenberg PDF converter and Gitea, and signs of Ivanti Sentry targeting. The malware's distinctive C2 mechanism hides its controller addresses in four keywords extracted from a poem ("On the Nature of Connection") stored in a dash.css file in a GitHub repository masquerading as a Node.js fork; changing the poem changes the C2, which the operator has done at least 11 times. Once inside, compromised servers run XMRig and Iron miners, communicate with the Russian mining service Kryptex, scan ports 3000/4000 and attempt to exploit CVE-2026-42271 in LiteLLM's MCP server endpoints — originally rated as requiring authentication until Horizon3 showed it chains with CVE-2026-48710 for unauthenticated RCE. BLL assesses with moderate confidence the operator is Italian; no confident attribution.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-10-08 |
| Source | BleepingComputer |
| Reliability | Tier 2 |
| CVEs | CVE-2026-42271, CVE-2026-48710 |