PoeLLM 'Canto Incognito' botnet infects 3,400+ servers, decoding C2 addresses from a GitHub-hosted poem
Lumen's Black Lotus Labs says PoeLLM malware has compromised more than 3,400 exposed servers since April 2026, deriving command-and-control IPv4 addresses from words in a GitHub poem while running XMRig and Iron cryptominers.
Lumen Technologies' Black Lotus Labs reports that PoeLLM, a Linux malware tracked as the 'Canto Incognito' campaign, has compromised more than 3,400 servers since at least April 2026, mainly in the United States and Western Europe; The Register puts the figure above 3,000 and BleepingComputer above 2,100, with peak activity of roughly 800 infections in a single day. The malware exploits exposed open-source services including LiteLLM, Ollama, Gotenberg, and Gitea; BleepingComputer, The Hacker News, Help Net Security, and The Register also implicate Ivanti Sentry, while GBHackers says only possibly. Its command-and-control IPv4 address is assembled from four words in a poem hosted on GitHub, mapped through a hard-coded dictionary, letting operators rotate infrastructure by editing the poem — done 11 times per Help Net Security, matching BleepingComputer's report of at least 11 controllers. Compromised hosts scan for new victims (on ports 3000 and 4000 per Help Net Security), deploy exploits, open remote shells, run XMRig and Iron miners tied to the Russian Kryptex service, and have begun experimenting with distributed SSH brute-force attacks; CyberScoop adds that the remote code execution capability could be used to abuse AI models on victim servers. Vulnerabilities cited include LiteLLM CVE-2026-42271 — described variously as command injection (Cyber Security News, Help Net Security), authenticated command execution fixed in LiteLLM 1.83.7 (GBHackers), or chainable with CVE-2026-48710 for unauthenticated RCE (BleepingComputer) — plus Ivanti Sentry flaw CVE-2026-10520, which The Register says surfaced the activity during a separate investigation. Attribution is to an Italian-speaking, financially motivated operator with moderate confidence, based on Italian-language code comments and Italy-based servers, with no observed links to known groups; GBHackers reports Lumen blocked traffic to identified command servers.
- Lumen's Black Lotus Labs tracks the campaign as 'Canto Incognito'; PoeLLM has been active since at least April 2026, mainly affecting the US and Western Europe.
- Five of seven outlets (CyberScoop, The Hacker News, GBHackers, Cyber Security News, Help Net Security) report more than 3,400 compromised servers; The Register says more than 3,000 and BleepingComputer says more than 2,100.
- Peak activity reached roughly 800 infections in a single day — 'as many as 800 active in one day' per BleepingComputer and 'above 800 daily' per GBHackers.
Coverage timelineoldest first · each row is one article
- · 1d agoPoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
CyberScoop· 77
PoeLLM malware has compromised over 3,400 servers, encoding its command-and-control address in a GitHub poem.
- · 1d agoPoeLLM malware infects exposed AI servers in cryptomining attacks
BleepingComputer· 76
PoeLLM cryptomining malware has compromised over 2,100 exposed AI servers, using GitHub poems for command-and-control.
- · 1d agoPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
The Hacker News· 74
Vulnerabilities in this storyAll →
- CVE-2026-1052010.0100%Unauthenticated OS Command Injection in Ivanti Sentrypublished · Ivanti Sentry (formerly MobileIron Sentry) KEV PoC