Skip to content
Tech News
← Back to articles

Cryptomining malware PoeLLM hits over 3,400 servers via poem-based C2, Black Lotus Labs finds

read original more articles
GoKawiil Brief

Lumen's Black Lotus Labs reports that a campaign called Canto Incognito has infected more than 3,400 servers since April 2026 using malware dubbed PoeLLM, which deploys XMRig and Iron cryptominers linked to Kryptex mining infrastructure. The malware hides its command-and-control addresses inside words of a two-stanza poem posted on GitHub, edited 11 times to redirect infected machines to new servers, and primarily targets exposed AI/LLM tools like LiteLLM, Ollama, Gotenberg, Gitea, and possibly Ivanti Sentry.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The use of poetry is purely an encoding trick for server addresses, not an AI jailbreak, but it shows attackers experimenting with unconventional methods to evade detection of C2 infrastructure. Lumen suggests the campaign is likely financially motivated, given many victims connected to a Russian crypto mining service, and warns that exposed AI infrastructure is an increasingly attractive target due to valuable data and GPU access. Lumen says it has blocked traffic to the known C2 servers, though vulnerable AI deployments elsewhere could remain exposed.

Key Takeaways

Source: tomshardware.com — Shane Downing, 2026-10-11

Published there as: “Cryptomining malware used poetry to infect more than 3,400 servers, researchers say”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.