PoeLLM Malware Hides C2 Addresses in GitHub Poems, Infects 3,000+

Lumen's Black Lotus Labs says PoeLLM malware infected over 3,000 servers, hiding C2 addresses in poems on GitHub to mine cryptocurrency on AI infrastructure.
Table of Contents
    Add a header to begin generating the table of contents

    Lumen’s Black Lotus Labs has reported that a malware campaign called PoeLLM has infected more than 3,000 servers, using poems posted to GitHub to hide the addresses of its command-and-control servers. The researchers published their findings on October 7.

    The campaign, which the researchers dubbed “Canto Incognito,” targets exposed AI and developer infrastructure and uses the compromised machines for cryptocurrency mining.

    Poems on GitHub Conceal the Command-and-Control Addresses

    The novel element of PoeLLM is how it finds its controllers. Black Lotus Labs says the operators embed command-and-control addresses in the text of poems posted to GitHub, a technique the researchers describe as “adversarial poetry.” The poems are meant to keep the addresses from appearing as ordinary network indicators.

    The researchers suspect an Italian-speaking operator. The first GitHub commit tied to the campaign dates to April 13, 2026, which means the activity has run for roughly six months before this public report.

    The Mining Payloads Run on Compromised GPUs

    The payloads are the XMRig and Iron cryptocurrency miners, both configured to connect to Kryptex infrastructure. Black Lotus Labs reports that the malware uses compromised GPUs for mining, which makes AI servers with graphics hardware particularly valuable to the operators.

    Scale and Targets of the Canto Incognito Campaign

    Black Lotus Labs counted more than 3,000 infected servers, with infections peaking at more than 800 active per day. Victims are concentrated in the United States and Western Europe.

    The targeted software is internet-facing LiteLLM, Ollama, Gotenberg and Gitea instances. The researchers also say the campaign may have affected Ivanti Sentry, tied to CVE-2026-10520, and note that an Ivanti Sentry victim contacted the command-and-control server in early June.

    Why AI Infrastructure Is the Target

    The affected products fall into two groups: tools for running or fronting language models, and developer services such as document conversion and code hosting. Instances of these products that are reachable from the internet give the operators a place to run mining software without buying hardware. For owners, the cost shows up as stolen compute and electricity, and as a foothold on a server that may hold other data.

    The report does not describe the specific access methods used against each product beyond the exposure of the services themselves.

    The infection count is large for a campaign that depends on exposed services. Black Lotus Labs’ figure of more than 3,000 infected servers, with a peak above 800 active infections in a single day, shows how large the operation grew over its run. The payload choice also fits the targets: XMRig and Iron are mining programs, and the GPUs attached to many AI servers are the hardware the researchers say the malware puts to work.

    Indicators Published and Response

    Black Lotus Labs published indicators of compromise so that defenders can look for the activity. The researchers urged operators to patch affected software and to remove public exposure of the services involved.

    Detection Challenges the Poetry Technique Creates

    Hiding addresses in prose rather than in code or configuration files is aimed at evasion. A poem on a legitimate hosting platform does not resemble the lists of domains and IP addresses that security tools typically flag, and the platform itself is one that many organizations allow through their networks. Black Lotus Labs frames the method as a deliberate attempt to avoid detection.

    The six-month duration and the daily peak of more than 800 active infections show an operation that has run at scale for months. The report does not state how much cryptocurrency the operators earned.

    Organizations that run LiteLLM, Ollama, Gotenberg or Gitea facing the internet can use the published indicators to check for infection. The researchers’ guidance on patching and removing public exposure applies to every product in the list.

    Related Posts