Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
PoeLLM cryptomining botnet infected 3,400+ servers running exposed LiteLLM, Ollama, and Gotenberg, decoding C2 addresses from a GitHub poem.
Black Lotus Labs tracks the 'Canto Incognito' campaign, active since April 2026 and attributed to an Italian-speaking financially motivated actor, which has compromised more than 3,400 servers, mostly in the US and Western Europe. The PoeLLM malware exploits vulnerable internet-exposed open-source services including LiteLLM (command injection, CVE-2026-42271), Ollama, Gotenberg, Gitea, and an Ivanti Sentry flaw (CVE-2026-10520), then deploys XMRig and Iron miners using the Russian Kryptex pool. C2 IPv4 addresses are decoded from four fixed words in a poem stored in a GitHub repository, edited 11 times to rotate C2 servers. Infected machines scan for new victims on ports 3000 and 4000 and have begun experimenting with distributed SSH brute-force attacks.