PoeLLM cryptomining malware hits over 3,400 servers via exposed AI services
Lumen's Black Lotus Labs says the Canto Incognito campaign, tracked since April 2026, has infected more than 3,400 servers, mostly running exposed AI services such as LiteLLM, Ollama, Gotenberg and Gitea. The malware derives its command-and-control address from a poem on GitHub that has been altered 11 times.
- Over 3,400 victim servers hit; campaign tracked since April 2026
- C2 address encoded in four words of a GitHub poem, changed 11 times
- Payload uses XMRig and Iron miners tied to Kryptex infrastructure
- Targets include LiteLLM, Ollama, Gotenberg and Gitea; patch LiteLLM 1.83.7+
Read next
Security