Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
PoeLLM cryptomining botnet infected 3,400+ servers running exposed LiteLLM, Ollama, and Gotenberg, decoding C2 addresses from a GitHub poem.
Black Lotus Labs tracks the 'Canto Incognito' campaign, active since April 2026 and attributed to an Italian-speaking financially motivated actor, which has compromised more than 3,400 servers, mostly in the US and Western Europe. The PoeLLM malware exploits vulnerable internet-exposed open-source services including LiteLLM (command injection, CVE-2026-42271), Ollama, Gotenberg, Gitea, and an Ivanti Sentry flaw (CVE-2026-10520), then deploys XMRig and Iron miners using the Russian Kryptex pool. C2 IPv4 addresses are decoded from four fixed words in a poem stored in a GitHub repository, edited 11 times to rotate C2 servers. Infected machines scan for new victims on ports 3000 and 4000 and have begun experimenting with distributed SSH brute-force attacks.
- PoeLLM botnet hit 3,400+ servers since April 2026, mostly US and Western Europe
- C2 IPv4 address decoded from four words in a GitHub-hosted poem, rotated 11 times
- Exploits LiteLLM command injection (CVE-2026-42271) and Ivanti Sentry flaw (CVE-2026-10520)
- Runs XMRig and Iron miners via Kryptex pool; bots self-propagate and brute-force SSH
Vulnerabilities mentionedAll →
- CVE-2026-1052010.0100%Unauthenticated OS Command Injection in Ivanti Sentrypublished · Ivanti Sentry (formerly MobileIron Sentry) KEV PoC
Full article770 words · extracted from helpnetsecurity.com · click to collapse
Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs.
The malware reading it, dubbed PoeLLM, breaks into exposed AI services and open-source tools, mines cryptocurrency on them and uses them to hunt for new victims.
The researchers call the campaign Canto Incognito and believe it is the work of an Italian-speaking threat actor who appears to be in it for the money. The operation has been running since April 2026 and has hit more than 3,400 servers, most of them in the US and Western Europe.

Canto Incognito campaign overview (Source: Black Lotus Labs)
“Most victims appear to be running vulnerable versions of open-source AI/LLM services, such as LiteLLM and Ollama. The malware also affected hundreds of servers running an open-source PDF converter called Gotenberg and the software development toolkit Gitea,”researchers wrote.
According to the researchers, attackers have realized that servers running AI/LLM implementations are worth compromising for two reasons. They can be a source of intelligence, and they are self-hosted, internet-exposed services with known vulnerabilities.
How it was found
The team first came across PoeLLM while looking into an Ivanti Sentry vulnerability (CVE-2026-10520).
“In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122. Shortly after contacting this C2, the Ivanti Sentry victim began scanning for other vulnerable devices,”
“Black Lotus Labs telemetry revealed the first GitHub commit with the poem that concealed the C2 address was made on April 13. Early traffic from the first known C2 router suggested the operator was testing the infection and payload downloads for a brief period,” they noted.
Starting in May, the attacker scanned the internet mostly for ports 3000 and 4000, the default ports for Gotenberg and LiteLLM. When a vulnerable server turned up, an exploit server sent it a crafted POST request instructing it to download a file from the C2 server.
In the sample Black Lotus Labs analyzed, the targeted LiteLLM endpoint (/mcp-rest/test/connection) is referenced in CVE-2026-42271, a command injection vulnerability in LiteLLM.
A poem as an address book
The poem, titled “On the Nature of Connection,” is stored in a file called dash.css in a GitHub repository set up by a user named “ejejejdfbbebe.” The repository is a fork of the nodejs.org website source code, though the malware has no link to Node.js.
PoeLLM extracts four words from fixed spots in the poem and matches each to a number using a dictionary hard-coded in the malware. The four numbers make up the IPv4 address of the current C2 server. In one earlier version of the poem, the words “driver,” “diode,” “decryption” and “string” translated to 92, 119, 165 and 74, which gave the C2 address 92.119.165.74.

Breakdown of C2 poem conversion key from a sample found on June 23, 2026 (Source: Black Lotus Labs)
When the attacker sets up a new C2 server, they change those four words in the GitHub repository and infected machines work out the new address on their own. The poem has been edited 11 times since the first commit on April 13, 2026, and each edit sent victims to a new server.
“At the time of writing, the malware creator has not changed the pattern used in deciphering the poem. Only the keywords have changed over the 11 iterations we have observed, they noted.
Mining, scanning and brute-forcing
Once installed, the malware runs the XMRig and Iron cryptocurrency miners and connects victims to the Russian Kryptex mining pool. It also comes with a remote shell, HTTP/S scanning and exploit deployment features. Infected servers are put to work scanning for and exploiting new targets, which is how the botnet grows.
More recently, groups of bots started targeting SSH ports and other login portals. The researchers say this indicates the operator may be experimenting with distributed brute-force attacks, though the capability appears to be in the early stages of development.
Black Lotus Labs says it has blocked traffic to and from the PoeLLM C2 servers and will keep monitoring for new traffic.
“As AI becomes more involved in both development and day-to-day operations, and enterprises rapidly expand their attack surface by including AI infrastructure, the security of these agents cannot take a backseat to convenience”
“Delays in updating internet-facing AI and enterprise tools enable highly trusted access. Incorporating AI tools into attack surface management and patch and update cycles is critical not only to protect enterprises from abuse of token usage and cryptomining, as evidenced in this campaign, but more critically from data loss, LLM jacking and lateral movement,” researchers concluded.