PoeLLM Malware Infects 3,400+ Servers in Crypto Botnet — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Lumen Black Lotus Labs identified the "Canto Incognito" campaign that has infected 3,400+ servers since April 2026, deploying XMRig and Iron miners that connect victims to Russian crypto-mining service Kryptex
- The PoeLLM malware hides its command-and-control address inside a poem hosted on a GitHub repository ("github[.]com/ejejejdfbbebe," first committed April 13, 2026), deriving the C2 from key words the threat actors swap out each rotation
- Threat actors primarily target exposed enterprise AI/LLM and document infrastructure including LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances to abuse their compute power for mining
- Compromised hosts are repurposed as exploit servers that send HTTP POST requests to exposed ports on identified targets, instructing them to pull the malware from the C2 and join the botnet
- At the mid-June peak, nearly 2,200 servers were affected with roughly 800 active per day; infections concentrate in the U.S. and Western Europe, and newer SSH traffic suggests the actors are experimenting with distributed brute-force attacks
- Lumen attributes the activity to an Italian-speaking threat actor with moderate confidence, citing Italian-language artifacts and netflow indicators
Why it matters: Lumen's finding reframes exposed AI infrastructure as a compute resource, not just a data-theft one — the 3,400 infected servers (peaking near 2,200 in mid-June) give the botnet both mining output and built-in scanning capacity to recruit more victims. Operators running LiteLLM, Gitea, or Ivanti Sentry appliances now face a concrete, ongoing exposure risk with active exploitation underway.
Ask SkimNews




