Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-08 · updated: 2026-10-08 · tags: [incident, global] · confidence: high · severity: high · affected_sectors: [global] · au_impact: false
🎯 IOCs · XMRIG
Indicators of compromise · XMRIG — 1 shown
  • 0ad68d5804804c25a6f6f3d87cc3a3886583f69b7115ba01ab7c6dd96a186404sha256 · ThreatFox · first seen 2026-09-25

Defanged third-party indicators (abuse.ch). The defanging is deliberate: never click, resolve or fetch these values. An indicator corroborates a report — it never proves one, and its presence here does not mean this story's hosts are listed.

Lumen's Black Lotus Labs reported that PoeLLM, active since at least April, has compromised more than 3,400 servers — peaking at 800 active in a single day — largely in the US and Western Europe, with victims running exposed AI services such as LiteLLM and Ollama, plus the Gotenberg PDF converter and Gitea, and signs of Ivanti Sentry targeting. The malware's distinctive C2 mechanism hides its controller addresses in four keywords extracted from a poem ("On the Nature of Connection") stored in a dash.css file in a GitHub repository masquerading as a Node.js fork; changing the poem changes the C2, which the operator has done at least 11 times. Once inside, compromised servers run XMRig and Iron miners, communicate with the Russian mining service Kryptex, scan ports 3000/4000 and attempt to exploit CVE-2026-42271 in LiteLLM's MCP server endpoints — originally rated as requiring authentication until Horizon3 showed it chains with CVE-2026-48710 for unauthenticated RCE. BLL assesses with moderate confidence the operator is Italian; no confident attribution.

Attribute Detail
Sector Global (Macro)
Date 2026-10-08
Source BleepingComputer
Reliability Tier 2
CVEs CVE-2026-42271, CVE-2026-48710