Poem-Based Malware PoeLLM Infects 3,400+ Servers
Black Lotus Labs reports the Canto Incognito campaign hid command-and-control servers behind a poem on GitHub that was changed 11 times.
Lumen's Black Lotus Labs reported that a cryptomining malware campaign tracked as Canto Incognito, built around malware named PoeLLM, infected more than 3,400 victim servers. Infected machines were turned into scanners and exploit servers as the campaign spread.
According to Lumen, the malware took its command-and-control instructions from a two-stanza poem titled "On the Nature of Connection" published on GitHub. The poem was changed 11 times, and each new version pointed infected hosts to a different C2 server. Lumen said it blocked all traffic to and from the PoeLLM C2 servers.
The payload consists of XMRig and Iron miners connected to Kryptex mining infrastructure. Most victims appeared to be running vulnerable versions of open-source AI/LLM services, including LiteLLM and Ollama.
At the time Lumen published its report, three of the 12 C2 servers were still active and the campaign continued to infect new victims. The poem was first committed in April, broad scanning began in May, and the likely exploitation path for LiteLLM was a crafted POST to the connection endpoint tied to CVE-2026-42271, which CISA added to its exploited vulnerabilities list in June.
Prior fix and target list
An April LiteLLM fix probably patched the exploitation path used by the malware. The primary targets include LiteLLM, Gotenberg, Ollama, Gitea and possibly Ivanti Sentry.
The primary commonality among the first 900 victims was contact with an endpoint for a Russian crypto mining service. Ivanti Sentry may also have been targeted, and one instance was how Lumen discovered the campaign. The advisory recommends LiteLLM 1.83.7 or later and Ivanti Sentry R10.5.2, R10.6.2, or R10.7.1.
Quick answers
What is PoeLLM?
PoeLLM is cryptomining malware reported by Lumen's Black Lotus Labs as part of a campaign tracked as Canto Incognito. It infected over 3,400 victim servers.
How did PoeLLM receive commands?
It used four words in a two-stanza poem on GitHub, changed 11 times, to point infected hosts to new command-and-control servers.
Which services were targeted?
Most victims appeared to run vulnerable versions of open-source AI/LLM services such as LiteLLM and Ollama. The primary targets include LiteLLM, Gotenberg, Ollama, Gitea and possibly Ivanti Sentry.