# Researchers trace cryptomining campaign across more than 3,400 servers

_Published Sunday, October 11, 2026 at 9:06 AM EDT · Security · Latest · Tier 2 — Notable_

![Illustration of a robot reading a book of poems at a desk while, through the window, a hooded man directs robots mining with pickaxes — Primary](https://cdn.mos.cms.futurecdn.net/aqPrPS4qzkg5HW3n7K9Ypn-809-80.png)

Cryptomining malware has hit more than 3,400 servers in an ongoing campaign, Lumen's Black Lotus Labs reports. The malware, called PoeLLM, exploits publicly exposed services and uses four words in a poem stored on GitHub to encode addresses for servers that direct infected hosts.

Its payload includes XMRig and Iron miners, and infected servers become scanners and exploit servers. Targets include LiteLLM, Ollama, Gotenberg and Gitea. Lumen identified a crafted request to LiteLLM as the likely exploitation path but did not detail the methods for the other services.

The poem's address encoding has changed 11 times. Three of the campaign's 12 command servers remained active when Lumen published its findings, and new infections continued.

## Sources

- [Tom's Hardware](https://www.tomshardware.com/tech-industry/cyber-security/cryptomining-malware-used-poetry-to-infect-more-than-3-400-servers-researchers-say-four-words-in-the-poellm-verse-changed-11-times-point-the-botnet-to-new-servers)

---
Canonical: https://techandbusiness.org/newswire/t7S7BhEHPcb0pwyt67ozv8
Published: 2026-10-11T13:06:25.137Z
Story chronology: 2026-10-11T11:45:00.000Z
Retrieved: 2026-10-11T20:06:33.094Z
Publisher: Tech & Business (techandbusiness.org)
