PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
PoeLLM malware has infected over 3,400 servers to build a cryptomining botnet called Canto Incognito.
Lumen Black Lotus Labs reported the Canto Incognito campaign, which has deployed PoeLLM malware since April 2026 to more than 3,400 servers, mainly in the United States and Western Europe. Infected hosts run XMRig and Iron cryptocurrency miners and connect to the Kryptex mining service. The malware derives its command-and-control address from selected words in a poem hosted on GitHub. It exploits exposed LiteLLM, Gotenberg, Gitea, and Ivanti Sentry systems, then turns victims into scanners that push the malware to new targets. Lumen attributes the activity to an Italian-speaking actor with moderate confidence.