Skip to content
Sıfırıncı Dakika
Latest

Cryptomining malware hidden in poetry infected over 3,400 servers

Security1 min read

In brief

Lumen's Black Lotus Labs says PoeLLM, a cryptomining malware tracked since April 2026 in a campaign called Canto Incognito, has compromised more than 3,400 servers. The malware uses four words from a two-stanza poem on GitHub as address encoding to redirect hosts to new command-and-control servers. Most victims run vulnerable versions of open-source AI services such as LiteLLM and Ollama.

  • PoeLLM malware compromised over 3,400 servers
  • C2 addresses hidden in a GitHub poem, changed 11 times
  • Targets open-source services like LiteLLM, Ollama, Gotenberg and Gitea
  • XMRig and Iron miners connect to Kryptex infrastructure
  • Lumen blocked all traffic to and from the C2 servers

What happened?

Lumen's cybersecurity research team Black Lotus Labs says PoeLLM, a cryptomining malware tracked since April 2026 in a campaign dubbed "Canto Incognito," has compromised more than 3,400 servers.

A command center hidden in a poem

The most striking part is the command-and-control (C2) mechanism. Four words in a two-stanza poem called "On the Nature of Connection," published on GitHub, are converted into an IPv4 address that points infected hosts to a new C2 server. The poem has been changed 11 times so far. Researchers say the poem is "a perfect vehicle for hiding an important message."

Which systems are targeted?

Most victims run vulnerable versions of open-source AI services such as LiteLLM and Ollama. LiteLLM is an AI Gateway that lets companies route their apps to many models through one endpoint, while Ollama runs open-weight models on your own hardware. The list also includes Gotenberg, a PDF conversion API, and Gitea, a self-hosted Git platform. Enterprise gateway appliance Ivanti Sentry may also have been targeted.

Why it matters

The malware runs XMRig and Iron miners connected to Kryptex mining infrastructure, and infected servers become scanners and exploit servers. Lumen says the primary commonality among the first 900 victims was contact with a Russian crypto mining service, suggesting a financial motive. The firm says it has blocked all traffic to and from the PoeLLM C2 servers.

What to do

Check connection logs for the indicators of compromise listed on Lumen's GitHub page. Audit external exposure when installing any open-source tool and close unnecessary ports. Upgrade to LiteLLM 1.83.7 or later, and Ivanti Sentry R10.5.2, R10.6.2 or R10.7.1.

Why it matters

AI infrastructure is rapidly becoming a prime target as misconfigured open-source services multiply. This is a concrete warning for companies to audit their LLM servers and exposed ports.

Sources

Related stories