Security researchers have identified a financially motivated campaign, dubbed Canto Incognito, that targets exposed AI and large language model infrastructure to deploy cryptocurrency miners. The malware, named PoeLLM, has infected more than 3,400 servers since April 2026, with activity peaking in mid-June at nearly 2,200 affected servers. Both The Hacker News and BleepingComputer report the same core details, and neither source indicates any disagreement on the campaign's scale or methods.
The malware's most distinctive feature is its command-and-control (C2) hiding technique: the address is embedded in a poem the attackers wrote and hosted in a GitHub repository. Each time the operators set up a new C2 server, they change a few words in the poem, and the malware derives the new address from those words. The first commit to the repository was made on April 13, 2026.
Targets include enterprise-facing deployments such as LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances. The attackers aim to abuse the compute power of these systems for illicit cryptocurrency mining, installing miners like XMRig and Iron and connecting victims to the Kryptex mining service. Some compromised hosts are repurposed to scan the internet for similar exposed instances and send HTTP POST requests that instruct them to download the malware, expanding the botnet. Lumen Black Lotus Labs attributes the activity to an Italian-speaking threat actor with moderate confidence, based on Italian-language artifacts and netflow indicators. The campaign also shows early experimentation with distributed brute-force attacks against SSH and other login portals, though that capability's maturity remains uncertain. Both sources agree that exposed AI infrastructure is becoming an attractive target because it runs on powerful hardware{