Cryptomining Botnet Hides Command Server in GitHub Poem, Infects 3,400+ Servers
A campaign dubbed Canto Incognito has deployed PoeLLM malware against thousands of machines running vulnerable AI infrastructure, using an ingenious steganographic technique to mask its control communications.

Researchers at Black Lotus Labs, the cybersecurity division of Lumen, have documented a widespread cryptomining operation targeting AI and machine learning services. The campaign, tracked under the name Canto Incognito since April 2026, has compromised more than 3,400 servers through deployment of PoeLLM malware.
The attack's most distinctive feature lies in its command-and-control infrastructure. Rather than relying on traditional domain names or IP addresses, the malware operators encoded server addresses within a two-stanza poem hosted on GitHub. Four specific words from the verse contain the necessary address information, and the attackers have modified this poem 11 times to redirect infected machines to new control servers as needed.
The majority of compromised systems appear to be running outdated versions of open-source AI and large language model services, particularly LiteLLM and Ollama. A vulnerability in LiteLLM received a patch in April, yet many operators have failed to apply the update, leaving their infrastructure exposed to exploitation.
Once installed, PoeLLM deploys XMRig and Iron cryptocurrency miners that connect to Kryptex mining infrastructure. The infected servers then function as both mining nodes and scanning and exploitation platforms for further compromise. Among the first 900 victims identified, a common thread emerged: contact with endpoints belonging to a Russian cryptocurrency mining service, suggesting financial motivation behind the operation.
The targeting of AI infrastructure reflects a broader shift in attacker priorities. According to Lumen, "AI infrastructure is becoming an attractive target" because exposed AI services frequently house sensitive data and provide access to valuable computational resources, particularly graphics processing units. The company has taken steps to mitigate the threat, stating it "has blocked all traffic to and from the PoeLLM C2 servers."