PoeLLM malware infects exposed AI servers in cryptomining attacks
Researchers said the botnet has compromised more than 2,100 servers and uses a poem-based lookup to rotate hidden command-and-control addresses.
- On Wednesday, Black Lotus Labs reported that PoeLLM malware has compromised more than 3,400 servers since April. The botnet uses a GitHub-hosted poem to hide command-and-control server addresses.
- Researchers identified the campaign as Canto Incognito, attributed to an Italian-speaking attacker. The malware extracts four specific words from a poem titled 'On the Nature of Connection' on GitHub, converting them into dynamic command-and-control addresses.
- PoeLLM deploys XMRig and Iron miners, connecting compromised systems to Kryptex mining infrastructure. By targeting vulnerable AI services like LiteLLM and Ollama, the botnet turns infected servers into launchpads for further exploits.
- At its peak, the malware infected more than 800 active servers daily, exploiting Ivanti Sentry and CVE-2026-42271. Victims running Gotenberg and Gitea also face risks as the botnet scans for additional vulnerable services.
- Because the operator updates the poem to rotate command-and-control locations, the botnet maintains high resiliency. BLL recommends administrators apply security updates, reduce public internet exposure, and inspect network logs for suspicious connections.
12 Articles
12 Articles
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
Quoth the LLM, 'More and more'
PoeLLM Malware Expands Cryptojacking Footprint
PoeLLM has reportedly infected more than 3,400 servers to grow a crypto-mining botnet, with compromised infrastructure repurposed for sustained illicit mining activity. The campaign, outlined in PoeLLM malware coverage, centers...
PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
More than 3,400 servers have been compromised by malware that hides its infrastructure coordinates in a poem.
PoeLLM malware infects exposed AI servers in cryptomining attacks
A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. [...]
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The malware reading it, dubbed PoeLLM, breaks into exposed AI services and open-source tools, mines cryptocurrency on them and uses them to hunt for new victims. The researchers call the campaign Canto Incognito and believe it is the work of an Italian-speaking threat actor who appears to be in it … …
Hackers Use GitHub-Hosted Poem to Control PoeLLM Malware Targeting AI Infrastructure
Hackers are using a poem hosted on GitHub to guide PoeLLM malware toward its command-and-control servers, turning exposed AI infrastructure into a growing cryptocurrency-mining botnet. The campaign targets internet-facing services, including LiteLLM and Ollama, while also affecting Gotenberg PDF converters and Gitea development servers. Active since at least April 2026, PoeLLM uses selected words in […]
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









