Cryptomining malware used poetry to infect more than 3,400 servers, researchers say

5 hours ago 7
Illustration of a robot reading a book of poems at a desk while, through the window, a hooded man directs robots mining with pickaxes (Image credit: Lumen)

Over 3,400 “victim servers” were hit by cryptomining malware PoeLLM during a campaign named Canto Incognito, tracked since April 2026, Lumen’s cybersecurity research team Black Lotus Labs reports. The malware’s “command-and-control (C2) mechanism” used address encoding through four words in a two-stanza poem on GitHub, altered 11 times so far, to direct affected hosts to new C2 servers. Most of those hit look to be running “vulnerable versions of open-source AI/LLM services, such as LiteLLM and Ollama,” despite an April LiteLLM fix that probably patched the exploitation path.

The malware’s payload consists of XMRig and Iron miners, connected to Kryptex mining infrastructure, with infected servers becoming scanners and exploit servers. The “primary commonality amongst the first 900 victims” was contact with “an endpoint for the Russian crypto mining service,” Lumen says. This indicates that it may be financially motivated. “AI infrastructure is becoming an attractive target” because exposed AI services may contain valuable data and hardware access, especially GPUs. In the meantime, it has “blocked all traffic to and from the PoeLLM C2 servers.”

Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.

Shane Downing is a Contributing Writer for Tom’s Hardware, covering consumer storage, PC hardware, and AI.

Read Entire Article