Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
PoeLLM malware has infected over 3,000 servers since April, hiding command-and-control in a GitHub poem while mining cryptocurrency.
Black Lotus Labs says the PoeLLM malware has infected more than 3,000 servers, mainly in the United States and Western Europe, since at least April 2026. The Canto Incognito campaign, linked to an Italian-speaking criminal, breaks into exposed services including LiteLLM, Ollama, Gotenberg, and Gitea. Infected hosts mine cryptocurrency with XMRig and scan for additional vulnerable systems. Operators hide command-and-control locations in a poem on GitHub; researchers found the activity while investigating Ivanti Sentry flaw CVE-2026-10520.
80