A Botnet Hid Its Next Address in a Poem and Mined Crypto on Exposed AI Servers

Lumen Technologies' Black Lotus Labs says it has blocked all traffic to and from the control servers of a cryptocurrency-mining network that has taken over thousands of internet-facing AI and developer servers since April 2026, and that finds its control server by reading a poem posted on GitHub.
Black Lotus Labs' report says exposed AI services draw attackers for reasons beyond their software flaws: they may hold useful data, and they run on powerful hardware well suited to mining. Most affected machines were running vulnerable versions of open-source tools, among them the AI model services LiteLLM and Ollama, the document converter Gotenberg and the developer platform Gitea. Victims were concentrated in the United States and Western Europe.
Black Lotus Labs gives two totals for how far the campaign spread: more than 3,400 servers affected in its summary of the findings, and almost 2,200 in the body of the report. Both sections put peak activity at nearly 800 servers active on a single day.
The lab says the malware takes a few keywords out of a poem kept in a public GitHub repository and uses them to work out which server to contact. When the operator rewrites those words, infected machines follow to the new address on their own. The poem has been rewritten 11 times. The lab counted 12 control addresses in all, three of them still active at the time it published.
Infected servers were not only mining. Black Lotus Labs says they were also turned into scanners and exploit servers hunting for more vulnerable machines, and that the miners in the payload connected victims to the Kryptex mining service.
Black Lotus Labs assesses with moderate confidence that the malware is associated with an Italian-speaking actor, citing Italian-language comments in a malware sample and the servers' network traffic. Its advice to defenders is about exposure: audit what a newly installed open-source tool opens to the internet, and keep service ports closed to the outside. Gotenberg's own installation guidance, which the report reproduces, already warns users not to expose the converter to the internet.
