CYBERSECURITY researchers have flagged a new malware family, PoeLLM, deployed in a campaign dubbed Canto Incognito that has compromised more than 3,400 exposed AI/LLM infrastructure instances to power cryptocurrency mining. The operation targets internet-facing enterprise tooling such as LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances, using compromised hosts to expand the botnet and to act as scanners and exploit servers for further compromises. The campaign is financially motivated, with miners including XMRig and Iron installed and the victims connected to Kryptex, a Russian mining service.
The infection workflow is notable for its stealthy C2 mechanism, which operators hide in a poem hosted in a GitHub repository; the malware derives the command-and-control address from words in the evolving poem, changing the address with each new C2 setup. Lumen Black Lotus Labs reports active exploitation has been ongoing since April 2026, with a peak in mid-June when around 2,200 servers were affected and nearly 800 remained active per day.
The campaign has also shown that some compromised systems are repurposed to scan the internet for similar targets and to push the malware to identified hosts via HTTP commands. Italian-language artefacts and network indicators have led researchers to attribute the activity, with moderate confidence, to an Italian-speaking threat actor. The objective, beyond mining, is to broaden the victim pool by exploiting publicly exposed services and converting affected machines into scanners.
Evidence and observations come from Lumen Black Lotus Labs’ analysis and the reported infection growth to date. The article does not specify mitigations or remediation steps.