PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
PoeLLM malware has infected over 3,400 servers to build a cryptomining botnet called Canto Incognito.
Lumen Black Lotus Labs reported the Canto Incognito campaign, which has deployed PoeLLM malware since April 2026 to more than 3,400 servers, mainly in the United States and Western Europe. Infected hosts run XMRig and Iron cryptocurrency miners and connect to the Kryptex mining service. The malware derives its command-and-control address from selected words in a poem hosted on GitHub. It exploits exposed LiteLLM, Gotenberg, Gitea, and Ivanti Sentry systems, then turns victims into scanners that push the malware to new targets. Lumen attributes the activity to an Italian-speaking actor with moderate confidence.
- More than 3,400 servers were infected since April 2026.
- Campaign installs XMRig and Iron miners and uses Kryptex.
- C2 address is derived from a poem hosted on GitHub.
- Targets include LiteLLM, Gotenberg, Gitea, and Ivanti Sentry.
- Compromised hosts are reused as scanners and exploit servers.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | github.com | the threat actors wrote and hosted in a GitHub repository ("github[.]com/ejejejdfbbebe"). The first commit to the repository was o |
Full article500 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 07, 2026Botnet / Cryptojacking
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.
The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service.
"Compromised hosts are reused to expand the botnet," Lumen Black Lotus Labs said in a report shared with The Hacker News. "Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems."
The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a "creative" technique that hides the command-and-control (C2) address within a poem the threat actors wrote and hosted in a GitHub repository ("github[.]com/ejejejdfbbebe"). The first commit to the repository was on April 13, 2026.
"Each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words," Ryan English, information security engineer at Lumen Technologies, told The Hacker News.
The attacks have been primarily found to single out enterprise, internet-facing deployments such as LiteLLM and Gotenberg, as well as Gitea and Ivanti Sentry appliances.
![]() |
| C2 Extraction Logic |
The targeting of these LLM instances is no coincidence as the intention is to abuse their compute power for illicit cryptocurrency mining. Evidence indicates that the malware has been active since April 2026, with more than 3400 victim servers identified so far. The infections are concentrated in the U.S. and Western Europe.
"At the peak of operations in mid-June, the campaign involved almost 2,200 affected servers, with nearly 800 active per day," the cybersecurity company said. "More recent traffic toward SSH and other login portals suggests experimentation with distributed brute-force attacks; that capability’s maturity remains uncertain."
Another notable aspect of the campaign is that it repurposes some of the compromised systems to scan the internet for similar instances, send an HTTP POST request to exposed ports on identified targets that instruct them to download the malware from the C2.
Lumen Black Lotus Labs has attributed the activity to an Italian-speaking threat actor with moderate confidence based on the presence of Italian-language artifacts and netflow indicators. The end goal of the campaign is to weaponize known vulnerabilities in publicly exposed services to enlist them into a cryptocurrency mining botnet and convert a subset of them into a scanner to expand the victim pool.
"AI infrastructure is becoming an attractive target," Lumen said. "Exposed AI/LLM services are valuable not only because of software vulnerabilities, but also because they may contain useful data and run on powerful hardware suitable for mining."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
