chiprook
← Security
SecurityOctober 11, 2026, 18:45

PoeLLM cryptomining malware hits over 3,400 servers via exposed AI services

Lumen's Black Lotus Labs says the Canto Incognito campaign, tracked since April 2026, has infected more than 3,400 servers, mostly running exposed AI services such as LiteLLM, Ollama, Gotenberg and Gitea. The malware derives its command-and-control address from a poem on GitHub that has been altered 11 times.

PoeLLM cryptomining malware hits over 3,400 servers via exposed AI services
#LiteLLM#Ollama#Gitea#Ivanti
Read next
Security

PoeLLM malware infects 2,100 AI servers in cryptomining attacks

Security

PoeLLM botnet mines crypto on AI servers via LiteLLM flaw

Security

Attackers use GitHub poem to infect thousands of servers with malware

Security

RatHat shifts to malware-as-a-service with three C2 generations in six months