Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Canto Incognito. Show all posts

PoeLLM Campaign Compromises 3,400+ Servers for Crypto Mining


Cryptocurrency mining campaigns have compromised over 3,400 servers since April 2026, with attackers primarily targeting exposed artificial intelligence and large language model infrastructures. The campaign is referred to as Canto Incognito and exploits vulnerable internet-facing services through PoeLLM malware, which becomes part of a growing mining botnet by exploiting vulnerable internet-facing services. 

Infections have largely been reported in the U.S. and Western Europe with nearly 2,200 affected servers at its peak at mid-June. Lumen Black Lotus Labs has reported that the malware has affected enterprise deployments such as LiteLLM, Ollama, Gotenberg, Gitea, and possibly Ivanti Sentry. 

The choice of artificial intelligence-based infrastructure has a significant impact on cryptocurrency mining due to the substantial computing resources that such systems are capable of providing. Some of the compromised servers may also be used to scan for additional vulnerable systems, which can help the attacker expand the botnet once they have been compromised. 

PoeLLM stands out due to its unique command-and-control mechanism (C2) Instead of placing the server address directly in the malware, the attacker concealed it in a poem hosted on GitHub. On April 13, 2026, the repository was created under the username “ejejejdfbbebebe,” with the first relevant commit being recorded. Throughout the campaign's change to its C2 infrastructure, the poem, titled "On the Nature of Connection," has been modified several times. 

By using a dictionary embedded in its code, the malware extracts selected words from fixed sections of the poem and maps them to numerical values. Those values are combined to determine the IPv4 address of the active C2 server. If the attacker changes the selected words, infected systems will be able to determine the new address without requiring a new sample of malware. 

A campaign's effectiveness is not only determined by the initial compromise. Once PoeLLM gains access to a compromised server, it can use the compromised system to locate additional targets. Black Lotus Labs observed a significant amount of scanning activity involving ports 3000 and 4000, which are commonly used to access Gotenberg and LiteLLM deployments. In order for vulnerable systems to retrieve malware from the active C2 infrastructure, crafted HTTP requests were sent to them. LiteLLM was a significant target in this activity. 

The analyzed malware sample referenced CVE-2026-42271, a command injection vulnerability associated with /mcp-rest/test/connection. In addition to providing attackers with access to exposed artificial intelligence infrastructure, PoeLLM also features cryptocurrency mining capabilities. This allowed attackers to launch further attacks on compromised systems. 

Infection involves the deployment of XMRig and Iron miners as well as the connection of compromised systems to the Kryptex mining service. The attackers can benefit greatly from the use of AI infrastructure because many such environments are run on advanced hardware with GPUs capable of providing significant computing power for mining. 

The malware does not limit itself to mining. According to researchers, infected servers are able to perform additional malicious activities by using remote shell functionality, HTTP/S scanning, and exploit deployment. Recent activity against SSH ports and other login interfaces suggests that the operator may also be testing distributed brute-force attacks, though this capability is currently at an early stage. As a result of assessing the campaign with moderate confidence, Black Lotus Labs has determined that the attacker is an Italian-speaking individual. 

A combination of Italian-language comments found on malicious software and associated GitHub pages, as well as network traffic analysis, contributed to the assessment. There has been no identification of a specific individual or established criminal group. 

In this campaign, it illustrates the dual purpose of exposed artificial intelligence infrastructure for attackers: its computing resources can be monetized, while compromised machines are also able to assist in locating and compromising the next set of vulnerable systems. 

Recent attack by hackers motivated by financial gain has demonstrated how exposed AI and developer infrastructure can become valuable targets for attackers with financial motivations. As AI deployments expand across enterprises, strong patching, restricted internet exposure and proactive monitoring remain essential.