A new malware family has infected more than 3,400 servers worldwide by targeting exposed artificial intelligence and large language model infrastructure to deploy cryptocurrency miners and grow a sprawling botnet, according to a report published by Lumen Black Lotus Labs. The financially motivated operation, called Canto Incognito, installs crypto mining software like XMRig and Iron and links compromised systems to Kryptex, a Russian cryptocurrency mining platform. The malware behind the campaign—dubbed PoeLLM—hides its command-and-control address inside a poem hosted on GitHub, changing a few words each time a new server is set up so the malware can derive the new address from the altered text.
The infections have been concentrated in the United States and Western Europe since the campaign began in April 2026, the report states. At its height in mid-June, the operation controlled nearly 2,200 affected servers, with close to 800 active daily. The attackers have primarily targeted enterprise-facing deployments including LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances. Recent traffic aimed at SSH and other login portals points to experimentation with distributed brute-force attacks, though the maturity of this capability remains unclear.
The campaign repurposes a portion of the compromised servers to scan the internet for similar vulnerable instances, according to Ryan English, information security engineer at Lumen Technologies, who told The Hacker News that "each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words." Once a target is identified, the infected system sends an HTTP POST request to exposed ports, instructing them to download the malware from the command-and-control server. Lumen Black Lotus Labs has attributed the activity to an Italian-speaking threat actor with moderate confidence, based on Italian-language artifacts and network flow indicators. Compromised hosts are recycled to expand the botnet, with infected servers transformed into scanners and exploit servers that allow the attacker to find and compromise additional vulnerable systems.
The targeting of LLM infrastructure is intentional: these systems offer powerful computing resources ideal for illicit cryptocurrency mining, the report explains. "AI infrastructure is becoming an attractive target," Lumen said, noting that "exposed AI/LLM services are valuable not only because of software vulnerabilities, but also because they may contain useful data and run on powerful hardware suitable for mining." The campaign's goal is to weaponize known vulnerabilities in publicly exposed services, enlist them into a cryptocurrency mining botnet, and convert a subset into scanners that expand the victim pool. The first commit to the GitHub repository hosting the poem appeared on April 13, 2026, marking the campaign's public footprint. Organizations running internet-facing AI and LLM deployments face a dual threat: exploitation for computational power and potential data exposure from software flaws. The sophistication of hiding command infrastructure in plain sight—inside verse posted to a public code repository—demonstrates how attackers are adapting to evade traditional detection methods while scaling operations through self-propagating infection chains. As AI workloads increasingly run on exposed infrastructure, the attack surface for financially motivated campaigns will likely expand unless organizations lock down public-facing services and patch known vulnerabilities.

