# Researchers identify more than 3400 servers hit by PoeLLM mining malware

_Published Wednesday, October 7, 2026 at 10:43 PM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![Researchers identify more than 3400 servers hit by PoeLLM mining malware — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDjQ8O0UFcl1dpOxEJoAM0s1mXXZHJNpJF4uJV_4jg7UPhHlDEvGHVxHKtyZQpnFC4HC3stGB-jJOSYUB5vdayfwx_eWPq-0F_l_ViYZNcA768t1N95JWhhbhUzY8anGOjVSL06QtsKVv_mz4lKgGrBMNBckAtFPxaW-KuG3mbWuUJrsyJP2vdWVbq8r9P/s1700-nu-rw-lo-l85-e365/crypto.jpg)

Lumen Black Lotus Labs identified more than 3400 victim servers in a cryptocurrency-mining campaign targeting exposed AI services and other enterprise systems, The Hacker News reported. The campaign, active since April 2026, installs miners and reuses compromised hosts to scan for and exploit additional victims.

The PoeLLM malware derives its command-server address from changing words in a poem hosted on GitHub. Targets include LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances, with infections concentrated in the US and Western Europe. Recent traffic suggests experiments with distributed password guessing, whose maturity remains uncertain.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/poellm-malware-infects-3400-servers-to.html)

---
Canonical: https://techandbusiness.org/newswire/S6qRmMi-1cn6PXhwJROmsh
Published: 2026-10-08T02:43:57.564Z
Story chronology: 2026-10-07T15:33:51.000Z
Retrieved: 2026-10-08T05:43:32.324Z
Publisher: Tech & Business (techandbusiness.org)
