Cryptomining malware PoeLLM hits over 3,400 servers via poem-based C2, Black Lotus Labs finds
Lumen's Black Lotus Labs reports that a campaign called Canto Incognito has infected more than 3,400 servers since April 2026 using malware dubbed PoeLLM, which deploys XMRig and Iron cryptominers linked to Kryptex mining infrastructure. The malware hides its command-and-control addresses inside words of a two-stanza poem posted on GitHub, edited 11 times to redirect infected machines to new servers, and primarily targets exposed AI/LLM tools like LiteLLM, Ollama, Gotenberg, Gitea, and possibly Ivanti Sentry.
GoKawiil's interpretation of the reporting above, not reported fact.
The use of poetry is purely an encoding trick for server addresses, not an AI jailbreak, but it shows attackers experimenting with unconventional methods to evade detection of C2 infrastructure. Lumen suggests the campaign is likely financially motivated, given many victims connected to a Russian crypto mining service, and warns that exposed AI infrastructure is an increasingly attractive target due to valuable data and GPU access. Lumen says it has blocked traffic to the known C2 servers, though vulnerable AI deployments elsewhere could remain exposed.
- PoeLLM malware infected over 3,400 servers since April 2026 in a campaign called Canto Incognito.
- C2 addresses were encoded in a repeatedly edited poem hosted on GitHub, not used for AI prompt manipulation.
- Targets included exposed LiteLLM, Ollama, Gotenberg and Gitea instances, with mining tied to a Russian crypto service.
Source: tomshardware.com — Shane Downing, 2026-10-11
Published there as: “Cryptomining malware used poetry to infect more than 3,400 servers, researchers say”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.