What happened?
Lumen's cybersecurity research team Black Lotus Labs says PoeLLM, a cryptomining malware tracked since April 2026 in a campaign dubbed "Canto Incognito," has compromised more than 3,400 servers.
A command center hidden in a poem
The most striking part is the command-and-control (C2) mechanism. Four words in a two-stanza poem called "On the Nature of Connection," published on GitHub, are converted into an IPv4 address that points infected hosts to a new C2 server. The poem has been changed 11 times so far. Researchers say the poem is "a perfect vehicle for hiding an important message."
Which systems are targeted?
Most victims run vulnerable versions of open-source AI services such as LiteLLM and Ollama. LiteLLM is an AI Gateway that lets companies route their apps to many models through one endpoint, while Ollama runs open-weight models on your own hardware. The list also includes Gotenberg, a PDF conversion API, and Gitea, a self-hosted Git platform. Enterprise gateway appliance Ivanti Sentry may also have been targeted.



