Researchers at Lumen’s Black Lotus Labs say the PoeLLM cryptomining botnet has infected more than 3,400 servers. The campaign, called Canto Incognito, has been active since at least April 2026. The malware hides its command‑and‑control address inside a two‑stanza poem on GitHub, using four specific words that change whenever the attackers move to a new server. So far the poem has been altered 11 times.
How the infection spreads
Most of the compromised machines were running open‑source AI or large language model services such as LiteLLM and Ollama. An April 2026 fix for LiteLLM likely patched the route the malware used, but many servers remain exposed. Once a server is infected, PoeLLM drops XMRig and Iron mining tools that connect to the Kryptex mining pool. The infected host also becomes a scanner, looking for other vulnerable AI endpoints to hijack.
What this means for server owners
The attackers appear financially motivated, linking the first 900 victims to a Russian crypto‑mining service. AI infrastructure is attractive because it often runs on powerful GPUs that can be repurposed for mining. Lumen says they have blocked traffic to and from the PoeLLM control servers, but the threat remains for any AI service that is not properly secured.
Why it matters
If you host AI models or LLM services, an unpatched version could be turned into a crypto‑miner without your knowledge, draining electricity and hardware performance. Keeping AI software up to date and restricting internet access to model endpoints can reduce this risk. It remains unclear how many active miners are still operating after Lumen’s traffic block.