PoeLLM cryptomining malware hits more than 3,400 servers
Lumen says the campaign keeps adding victims even after it blocked traffic to known control servers.
Lumen’s Black Lotus Labs says a cryptomining campaign it tracked as Canto Incognito has infected more than 3,400 servers by abusing exposed AI and other internet-facing services. The malware, called PoeLLM, uses a poem on GitHub to steer victims to changing command-and-control servers, and the researchers say the campaign has been active since April 2026. The payload includes XMRig and Iron miners tied to Kryptex infrastructure, but the report stops short of naming a specific coin and instead points to financial motivation. Lumen says the most common targets include LiteLLM, Gotenberg, Ollama, and Gitea, and that it has blocked traffic to the known C2 servers while the campaign keeps adding victims. It also notes that some of the targeted products, including LiteLLM, had known fixes or advisories that should reduce exposure if applied.
Why it matters
The campaign is affecting exposed AI and other internet-facing services at scale, not isolated machines. For operators of LiteLLM, Gotenberg, Ollama and Gitea, it shows that leaving these services exposed can quickly turn them into mining hosts, while blocking known servers only addresses part of an active effort.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- Tom's Hardware