A cryptomining botnet hiding its control-server address inside a poem posted to GitHub has infected more than 3,000 servers since April 2026, according to research from Lumen Technologies’ Black Lotus Labs team published October 7, 2026. The malware, dubbed PoeLLM, and the broader operation behind it, which researchers named Canto Incognito, targets internet-exposed AI and developer infrastructure, including LiteLLM gateways, Ollama model runners, Gitea code-hosting instances, the Gotenberg document-conversion service, and Ivanti Sentry mobile gateway appliances. The Hacker News, which first reported the findings, put the compromised-server count even higher, at more than 3,400 machines.

The campaign is notable less for its scale, which is modest by botnet standards, than for its tradecraft. Instead of a conventional domain or hardcoded IP address, PoeLLM’s command-and-control location is encoded inside a poem the attacker wrote and committed to a public GitHub repository under the account “ejejejdfbbebe.” The approach lets the operator rotate infrastructure by quietly editing a handful of words, something defenders and automated scanners are unlikely to flag as malicious.

What Black Lotus Labs Found in the Canto Incognito Campaign

Black Lotus Labs, Lumen’s threat intelligence unit, traced the first GitHub commit containing the adversarial poem to April 13, 2026, with broader exploitation activity beginning that same month. Infections ramped through the spring and summer, reaching a reported peak of close to 2,200 compromised servers in mid-June, based on The Hacker News’ account of the research. Both The Hacker News and The Register cited more than 800 actively infected servers per day at the operation’s busiest point, a figure the researchers used to describe sustained, not one-off, exploitation.

Victim concentration skewed toward the United States and Western Europe, according to the reporting, consistent with where self-hosted AI tooling and developer platforms are most densely deployed. The researchers describe Canto Incognito as financially motivated rather than tied to espionage or disruption, with cryptocurrency mining as the end goal rather than data theft or ransomware deployment.

Inside PoeLLM: How a GitHub Poem Hides the Command Server

The mechanism that gave the malware its name is the detail security teams are talking about most. Ryan English, an information security engineer at Lumen Technologies, described the rotation process to The Hacker News this way: “Each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words.” Rather than fetching an IP from a static config file, the malware parses the public poem, extracts a key tied to specific words, and derives the current command-and-control address from it.

The Register reported that the poem has been edited roughly eleven times since the initial April commit, each revision quietly repointing infected machines at a new server without changing the GitHub repository’s appearance to a casual visitor. A page that looks like a stray creative-writing post doubles as a resilient, difficult-to-blocklist dead drop.

Why a Poem Instead of a Domain

Domains and IPs get sinkholed, blocklisted, or seized. A plain-text poem hosted on a legitimate, high-trust platform like GitHub carries none of those signals to automated defenses. Black Lotus Labs researchers told The Register that encountering this exact technique in a live campaign marked a first for the team: “This is a first for us,” they said, adding weight to the idea that attackers are increasingly borrowing content-hiding tricks associated with AI-generated text to slip past both human reviewers and machine classifiers.

Which AI and Developer Tools Attackers Are Exploiting

Canto Incognito doesn’t rely on a single flaw. Instead, it scans broadly for internet-facing instances of popular open-source and commercial tools that teams stood up quickly to support AI workloads, then exploits whichever is misconfigured or unpatched.

LiteLLM and Ollama

LiteLLM, an open-source proxy that lets teams route requests across different large language model providers through one API, and Ollama, a popular tool for running models locally, both appear on the target list. Neither is new software, but both saw a surge in self-hosted deployments through 2025 and 2026 as companies built internal AI tooling faster than their security teams could review it.

Gitea, Gotenberg, and Ivanti Sentry

Gitea, a lightweight self-hosted alternative to GitHub, and Gotenberg, a document and PDF conversion microservice, round out the open-source side of the target list. The commercial outlier is Ivanti Sentry, a mobile gateway appliance, where Black Lotus Labs linked at least one compromised deployment to a specific, actively exploited vulnerability rather than generic misconfiguration.

Target SoftwareCategoryKnown Flaw ExploitedRole in the Attack Chain
LiteLLMOpen-source LLM proxy/gatewayMisconfiguration / exposureInitial access to AI-adjacent infrastructure
OllamaLocal LLM runnerMisconfiguration / exposureInitial access, scanning target
GiteaSelf-hosted Git platformMisconfiguration / exposureInitial access, source-code host
GotenbergDocument/PDF conversion APIMisconfiguration / exposureInitial access via exposed API
Ivanti SentryMobile gateway applianceCVE-2026-10520 (CVSS 10.0)Pre-auth root command execution

The Ivanti Sentry Flaw Behind Some Infections

CVE-2026-10520 is an OS command injection vulnerability in Ivanti Sentry affecting versions before R10.5.2, R10.6.2, and R10.7.1. Multiple vulnerability trackers, including SentinelOne and CrowdSec, rate it at a maximum CVSS score of 10.0, meaning an unauthenticated remote attacker can run arbitrary operating system commands with root privileges on the appliance without any credentials. Security researchers tracking the flaw reported that exploitation attempts began within 24 hours of public disclosure, a turnaround that has become typical for perfect-score, pre-authentication bugs in enterprise gateway appliances throughout 2026.

Black Lotus Labs’ reporting ties at least one Ivanti Sentry compromise, observed reaching out to the campaign’s command infrastructure in June 2026, to this flaw. That timing lines up with the campaign’s reported peak, suggesting the Ivanti bug gave Canto Incognito a reliable, high-privilege entry point alongside its broader scanning of exposed AI tooling. Readers tracking appliance-level flaws at this severity will recognize the pattern from Shattered’s earlier coverage of the WSO2 API Manager flaw that also scored a perfect CVSS 10.0 and sat unpatched for months before exploitation caught up.

XMRig, Iron, and Kryptex: Where the Mined Crypto Goes

Once a server is compromised, PoeLLM deploys two cryptocurrency miners: XMRig, a widely abused open-source Monero miner that shows up in nearly every cryptojacking campaign tracked over the past five years, and a second miner the researchers identified as Iron. Mined proceeds are funneled through Kryptex, a Russian cryptocurrency mining service that pools compute from infected and legitimate machines alike and pays out based on contributed hashing power.

Routing stolen compute through a commercial pooling service rather than a private wallet is a pattern seen in other 2026 botnet activity tracked by Shattered, including the operators behind the Gentlemen ransomware affiliate’s GitLab CI/CD secrets theft, where stolen access was similarly monetized through infrastructure that doesn’t require the attacker to run their own payment rails.

Why Attackers Are Turning Infected Servers Into Scanners

Mining cryptocurrency isn’t the only job PoeLLM gives its victims. Black Lotus Labs found that compromised hosts are reused to expand the botnet itself. “Compromised hosts are reused to expand the botnet,” the researchers wrote, describing how infected servers are turned into scanners and exploit launchpads that hunt for the next vulnerable LiteLLM, Ollama, Gitea, or Gotenberg instance. That self-propagation loop is what let a campaign with a single operator reach thousands of victims across two continents without needing a large infrastructure footprint of its own.

It also means takedown efforts face a moving target. Blocking one command server, or even seizing the GitHub repository hosting the poem, doesn’t stop already-infected hosts from continuing to scan and infect new victims on the attacker’s behalf.

Tracing the Attacker: Italian-Language Clues and Netflow Data

Attribution in the reporting is described as moderate confidence, not certain. Comments embedded in the malware’s code and on the attacker’s GitHub pages are written in Italian, and Black Lotus Labs’ netflow analysis of traffic patterns around the command infrastructure points toward an operator based in Italy. Neither detail amounts to definitive proof of the attacker’s identity or location, and the researchers have not named an individual or a known criminal group as the operator behind the Canto Incognito name.

From Kinsing to PoeLLM: Cryptomining Botnets Keep Finding New Doors

PoeLLM is the latest entry in a lineage of self-propagating cryptomining malware that stretches back years. Kinsing, first documented extensively by Aqua Security and covered repeatedly by outlets including SecurityWeek and Infosecurity Magazine, built its botnet by scanning for exposed Docker daemon APIs, then using that access to disable rival miners, wipe logs, and install its own cryptocurrency mining payload on a cron-based persistence loop. That campaign has remained active for years precisely because misconfigured container and orchestration APIs keep getting exposed to the open internet faster than teams can lock them down.

PoeLLM follows the same economic logic with a 2026 twist: instead of Docker APIs, the exposed surface is the wave of AI gateways, model runners, and developer tooling that teams stood up to support large language model projects. The targets changed. The underlying mistake, internet-facing software with weak or absent authentication, did not.

How PoeLLM Compares to Other 2026 AI and Cloud Security Incidents

Canto Incognito is one data point in a broader 2026 pattern of AI-adjacent infrastructure carrying severe, sometimes perfect-score vulnerabilities. Earlier this year, GitLab’s AI Gateway shipped a flaw rated CVSS 9.9, and container runtimes have had their own run of trouble, including a Cloudflare Containers bug that leaked data across 18 hosts and a kernel-level container escape tracked as CVE-2026-80521 in Ubuntu. Separately, researchers at CloudSEK, cited by The Register, found an unrelated LiteLLM supply-chain compromise that potentially exposed more than 2,500 companies and 434,000 CI/CD pipelines worldwide, a different incident from Canto Incognito but one that underscores how much enterprise exposure now sits behind the same handful of AI tooling projects. CyberScoop’s coverage of the Black Lotus Labs findings corroborates the core server count and the poem-based command mechanism.

CampaignPrimary TargetYears ActiveReported ScaleMonetization
KinsingExposed Docker daemon APIs2020-presentThousands of attempts daily, per multiple vendor reportsDirect cryptomining (XMRig)
PoeLLM / Canto IncognitoExposed AI gateways and dev toolsApril 2026-present3,000+ servers, 800+ active/day at peakXMRig and Iron miners via Kryptex
CloudSEK-reported LiteLLM supply-chain incidentLiteLLM dependency chain2026 (separate incident)2,500+ companies, 434,000 CI/CD pipelines exposedNot specified in public reporting

Market and Industry Impact: What This Means for AI Infrastructure Vendors

None of the software named in the Black Lotus Labs research is inherently insecure. LiteLLM, Ollama, Gitea, and Gotenberg are all widely trusted, actively maintained projects. The problem the campaign exposes is deployment hygiene: teams racing to stand up internal AI tooling have, in many cases, skipped the authentication, network segmentation, and patch cadence they would apply to a traditional production database or web server.

That gap matters commercially as much as technically. Enterprises adopting self-hosted LLM infrastructure are making a bet that the cost savings and data control outweigh the operational overhead of securing yet another class of internet-facing service. Campaigns like Canto Incognito, run by a single attacker with no need for sophisticated zero-days, make a case that the overhead was underestimated. Expect procurement teams evaluating LiteLLM, Ollama, and similar tools to start asking vendors and internal platform teams pointed questions about default authentication, exposure by default, and patch SLAs before the next round of internal AI rollouts.

Historical Parallel: Why Exposed APIs Remain the Easiest Door In

Every generation of infrastructure has gone through this cycle. Docker daemons in the early 2020s, Kubernetes dashboards a few years later, and now AI gateways and model runners in 2026. The common thread the Kinsing-to-PoeLLM comparison makes clear is that attackers don’t need novel exploits when operators leave administrative interfaces reachable from the open internet with weak or default credentials. Shattered’s coverage of recent Kubernetes CVE patches and the broader rise in data theft tied to exploited infrastructure both point to the same root cause showing up across different layers of the stack.

What Comes Next: Five Predictions for AI Infrastructure Security

  • Expect CISA and vendor trackers to add more AI-tooling CVEs to active-exploitation lists through early 2027, following the same curve seen with container and API gateway flaws since 2022.
  • LiteLLM, Ollama, and similar open-source projects will likely move toward authentication-required defaults, shifting the burden away from operators who currently have to opt in to securing a fresh install.
  • More cryptomining and botnet operators will copy PoeLLM’s content-hiding technique, using legitimate platforms like GitHub, Pastebin, or code-sharing sites as dead drops rather than traditional domains.
  • Cyber insurers and enterprise security teams will start treating self-hosted AI tooling as its own asset category for exposure scanning, similar to how container registries and Kubernetes dashboards are already tracked.
  • Attribution on Canto Incognito will likely remain unresolved for months; financially motivated solo or small-crew operators rarely surface in formal indictments the way state-linked or ransomware-as-a-service groups do.

How to Check if Your LiteLLM, Ollama, or Gitea Deployment Is Exposed

Security teams don’t need to wait for a formal advisory to check their own exposure. A basic first step is confirming whether management or API ports for these tools are reachable from outside the corporate network at all, since most legitimate deployments have no reason to expose them publicly.

# Check whether a host's LiteLLM/Ollama-style API port is reachable from outside
# Run this from a machine OUTSIDE your corporate network, against your own host/IP
nmap -Pn -p 4000,11434,3000,3001 your-server-ip-or-domain

# If any of these report "open" and you did not intentionally expose them,
# the service is reachable from the public internet and should be
# placed behind a VPN, firewall allow-list, or authenticated reverse proxy.

Beyond the port check, teams running any of the five tools named in the Black Lotus Labs research should confirm patch levels against each project’s current release, rotate any credentials that may have been reachable from an exposed instance, and review outbound network logs for connections to unfamiliar GitHub raw-content URLs, a detail specific to how PoeLLM retrieves its command-and-control address.

Frequently Asked Questions

What is PoeLLM malware?

PoeLLM is cryptomining malware identified by Lumen Technologies’ Black Lotus Labs team that infects exposed AI and developer infrastructure, then hides its command-and-control address inside a poem published on GitHub.

How many servers has PoeLLM infected?

The Register reported more than 3,000 infected servers since April 2026, while The Hacker News cited a figure above 3,400. Both outlets reported a peak of more than 800 actively infected servers per day.

What software does the Canto Incognito campaign target?

Reported targets include LiteLLM, Ollama, Gitea, Gotenberg, and Ivanti Sentry, with the Ivanti Sentry compromises tied specifically to CVE-2026-10520, a CVSS 10.0 command injection flaw.

How does the malware hide its command-and-control server?

PoeLLM encodes its command server address inside a poem hosted on a public GitHub repository. The malware derives the current address from a key tied to specific words in the poem, letting the attacker rotate infrastructure by editing the text rather than registering new domains.

Who is behind PoeLLM and Canto Incognito?

The attacker has not been formally identified. Black Lotus Labs assesses with moderate confidence that the operator is based in Italy, citing Italian-language comments in the malware and on the attacker’s GitHub pages alongside netflow analysis.

What cryptocurrency miners does PoeLLM install?

Infected servers run XMRig, a widely used open-source Monero miner, alongside a second miner the researchers identified as Iron. Mining proceeds are routed through Kryptex, a Russian cryptocurrency mining service.

Is this the same as the LiteLLM supply-chain attack reported by CloudSEK?

No. The CloudSEK-reported incident, which The Register said potentially exposed more than 2,500 companies and 434,000 CI/CD pipelines, is a separate LiteLLM supply-chain compromise and is not part of the Canto Incognito campaign.

How can I tell if my organization is affected?

Check whether LiteLLM, Ollama, Gitea, Gotenberg, or Ivanti Sentry instances are reachable from the public internet, confirm patch levels against each project’s latest release, and review outbound connections to unfamiliar GitHub raw-content URLs, which is how PoeLLM retrieves its current command-and-control address.