Skip to main content
World Today News
  • Home
  • News
  • World
  • Sport
  • Entertainment
  • Business
  • Health
  • Technology
Menu
  • Home
  • News
  • World
  • Sport
  • Entertainment
  • Business
  • Health
  • Technology
Illustration of a robot reading a book of poems at a desk while, through the window, a hooded man directs robots mining with

PoeLLM Malware Infects Over 3,400 Servers, Lumen Researchers Say

October 11, 2026 Rachel Kim – Technology Editor Technology

Cryptomining malware named PoeLLM has infected more than 3,400 servers globally by pulling command-and-control addresses from a hidden GitHub poem, Lumen’s Black Lotus Labs reported.

    The Tech TL;DR:

  • Over 3,400 servers running exposed AI frameworks like LiteLLM and Ollama were compromised by the Canto Incognito botnet.
  • The malware reads an online poem (“On the Nature of Connection”) to dynamically resolve and update its command-and-control server addresses.
  • Compromised systems run XMRig and Iron cryptocurrency miners linked to Kryptex and scan networks for CVE-2026-42271 vulnerabilities.

The Anatomy of Canto Incognito and Exposed AI Infrastructure

The campaign, tracked under the moniker Canto Incognito, weaponizes publicly exposed enterprise AI services and containerized tools. Researchers at Lumen’s Black Lotus Labs observed peak activity reaching roughly 800 active infected systems on a single day, with operations heavily concentrating across the United States and Western Europe. BleepingComputer noted that the botnet rapidly scaled from an initial count of 2,100 detections up to 3,400 verified victim servers as telemetry data expanded. The primary targets include LiteLLM proxy servers, Ollama open-weight model instances, Gotenberg PDF conversion APIs, and Gitea development platforms. Because these services typically run on powerful GPU clusters natively optimized for intensive computational workloads, threat actors find them ideal for illicit mining operations.

PoeLLM Malware Infects Over 3,400 Servers, Lumen Researchers Say
Photo: theoutpost.ai

PoeLLM Retrieves Infrastructure Endpoints from a Poem

Unlike standard botnets hardcoding IP addresses or utilizing rigid domain generation algorithms, PoeLLM retrieves its infrastructure endpoints from an unlikely text source. BleepingComputer reported that the ELF file, disguised under the filename libgcrypt, fetches four distinct words or phrases from a poem titled “On the Nature of Connection.” This text is hosted within a dash.css file inside a GitHub repository that forks the nodejs.org website source code. Since its initial commit on April 13, 2026, the repository’s maintainer has modified the poem 11 times to shift infrastructure locations. Using a poem likely aided in obfuscation as it is a perfect vehicle for hiding an important message, the researchers told The Register.

# Conceptual parsing flow for PoeLLM C2 extraction
import requests

def resolve_c2_from_verse(github_raw_url):
    response = requests.get(github_raw_url)
    poem_text = response.text
    # Extract targeted keywords based on hard-coded dictionary offsets
    keywords = parse_target_words(poem_text)
    ipv4_address = translate_keywords_to_ip(keywords)
    return ipv4_address

Infected Hosts Mine Cryptocurrency and Scan for Victims

Once an environment falls victim to the payload, the host actively participates in network reconnaissance and secondary exploitation. The campaign leverages XMRig and Iron miners to funnel computational yields into the Kryptex Russian cryptocurrency mining service, with Lumen noting that the primary commonality amongst the first 900 victims was contact with an endpoint for the Russian crypto mining service. Furthermore, infected hosts transform into automated scanners targeting ports 3000 and 4000 to locate additional vulnerable instances. The malware is deployed through vulnerability exploitation of publicly exposed services, with broad scanning beginning in May. When combined with CVE-2026-48710, this vulnerability allows unauthenticated remote code execution.

PoeLLM malware infects exposed AI servers in cryptomining attacks

Analysts Link Malware Operator to Italy

Security analysts remain cautious regarding definitive threat actor attribution. While BleepingComputer noted that researchers hold moderate confidence that the operator is Italian—citing internal comments embedded within the malware code alongside Italy-based server hosting infrastructure—the identity of the repository owner operating under the GitHub handle “ejejejdfbbebe” remains under scrutiny. Infrastructure forensic analysis revealed that multiple command-and-control servers utilized vulnerable router administration interfaces, indicating that attackers likely recycled previously compromised edge hardware to shield their operational footprint. Ryan English, information security engineer at Lumen Technologies, noted that each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words. As enterprise cloud architectures continue to expand rapidly without proper perimeter isolation, security teams are strongly advised to audit external internet exposure, restrict network access to trusted IP ranges, patch vulnerable gateway appliances, and verify connection logs against Lumen’s published indicators of compromise.

Next Steps in Mitigating AI-Speed Attacks

Disclaimer: The technical analyses and security protocols detailed in this article are for informational purposes only. Always consult with certified IT and cybersecurity professionals before altering enterprise networks or handling sensitive data.

More on this story: Huntress: Malicious Custom GPTs distribute remote-access trojans · AI Agent Makes Failed Hacking Attempt on Canadian Government Website

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Worth a look

  • Van Cleef & Arpels ring sells for $458,858 at Sotheby’s Paris, per website
  • Astronomers Discover Rare Second-Generation Planet Candidate Orbiting White Dwarf

Related

Search:

World Today News

World Today News is your trusted source for global journalism — breaking headlines, in-depth analysis, and reporting from around the world.

Quick Links

  • Privacy Policy
  • About Us
  • Accessibility statement
  • California Privacy Notice (CCPA/CPRA)
  • Contact
  • Cookie Policy
  • Disclaimer
  • DMCA Policy
  • Do not sell my info
  • EDITORIAL TEAM
  • Terms & Conditions

Browse by Location

  • GB
  • NZ
  • US

Connect With Us

© 2026 World Today News. All rights reserved. Your trusted global news source directory.
For contact, advertising, copyright, issues email: office@world-today-news.com

Privacy Policy Terms of Service