A malware campaign called PoeLLM has compromised more than 3,400 servers by targeting exposed AI and open-source services, then turning those machines into cryptocurrency miners, vulnerability scanners, and launch points for new attacks. Its strangest trick is how infected systems find their command server: they read four changing words from a poem hosted on GitHub.
Lumen’s Black Lotus Labs calls the campaign Canto Incognito and says it has been active since at least April 2026. Most observed victims were running vulnerable internet-facing services such as LiteLLM, Ollama, Gotenberg, and Gitea. The malware can deploy XMRig and Iron miners, connect compromised systems to mining infrastructure, and reuse infected hosts to scan for additional targets.
The command server is hidden inside a poem
PoeLLM does not simply store one fixed command-and-control address inside the malware. Instead, it retrieves a short poem from a GitHub repository and extracts four specific words or phrases from fixed positions in the verse. A hard-coded conversion table turns those words into four numbers, which become an IPv4 address.
When the operator wants infected machines to use a new command server, only those key words need to change. Black Lotus Labs observed 11 poem revisions after the first commit on April 13. The structure stayed mostly the same while the important words changed, allowing infected systems to calculate a new address without replacing the malware binary.
Why AI servers are attractive cryptomining targets
Self-hosted AI infrastructure can combine three things attackers like: powerful CPUs or GPUs, internet-accessible services, and relatively new software stacks that administrators may not yet treat like mature production infrastructure. If a machine already has expensive compute installed, the attacker does not have to pay for the hardware or electricity needed to mine cryptocurrency.
That makes local-model infrastructure valuable even when the model itself is not the target. BitcoinVersus previously covered privacy-focused AI platforms including self-hosted tools such as Ollama. PoeLLM shows the other side of self-hosting: keeping inference local can improve data control, but the server still needs the same exposure management, patching, and monitoring as any other internet-facing system.
Exposed ports turned convenience into attack surface
Black Lotus Labs found large numbers of victims with services exposed directly to the public internet. The campaign scanned common service ports, identified vulnerable applications, and then reused already-compromised machines as additional scanning and exploitation workers.
This is where a basic networking concept becomes a security boundary. BitcoinVersus’ 127.0.0.1 and localhost explainer describes the difference between a service listening only on the local machine and one reachable through a network interface. A development service that is safe on loopback can become a completely different risk when it is bound publicly and left unfiltered.
The lesson is not that every LiteLLM or Ollama deployment is compromised. Exposure, vulnerable versions, and configuration all matter. The useful question for operators is whether a service that was intended for local or controlled access is now reachable from the public internet without a firewall, reverse proxy, authentication layer, or timely patching.
PoeLLM steals compute, then uses the victim to find more victims
Once installed, PoeLLM can run cryptocurrency miners and also turn the infected machine into part of the botnet’s expansion system. Researchers observed compromised hosts scanning other systems and forwarding exploit attempts, which reduces the attacker’s need to operate a large pool of infrastructure directly.
The operation has also shown signs of testing distributed attacks against SSH and other login portals. That capability was described as immature in the Black Lotus Labs research, so it should not be overstated as a proven large-scale brute-force operation. It does, however, show that the botnet can be repurposed beyond mining.
For administrators, SSH exposure deserves the same inventory discipline as AI APIs. BitcoinVersus’ SSH key explainer covers why key-based authentication is generally stronger than passwords, but authentication strength does not replace patching, rate limiting, network controls, or removing services that never needed to be public.
The 3,400 figure is servers, not companies
Black Lotus Labs says PoeLLM has impacted more than 3,400 victim servers and exceeded 800 active infected servers per day at peak activity. Those numbers should not be translated into 3,400 companies or 3,400 unique organizations. One operator may run many servers, and infrastructure can change over time.
Tom’s Hardware’s October 11 report highlights the same cumulative server count and the 11 poem changes, while noting that at least one likely LiteLLM entry path already had a fix available. The important operational point is that internet-facing software can remain exploitable long after a patch exists if deployments are never inventoried or upgraded.
What operators should check
- External exposure: Inventory AI gateways, local-model APIs, developer services, document converters, dashboards, and management interfaces reachable from the internet.
- Patch level: Update exposed services and review vendor advisories for vulnerabilities affecting the exact versions in use.
- Network behavior: Investigate unexpected mining-pool traffic, unexplained high CPU or GPU utilization, unusual outbound scanning, and connections to published PoeLLM indicators.
- Access controls: Restrict services to required networks, use firewalls or authenticated reverse proxies, and avoid exposing development defaults directly to the internet.
- Compromise scope: If a server is infected, treat it as more than a stolen-compute problem. Check credentials, adjacent systems, persistence, and outbound activity before returning it to service.
The poem is clever, but exposure is the bigger story
The poem makes PoeLLM memorable because it gives the operator a simple way to rotate command infrastructure through an ordinary public file. But the campaign did not compromise thousands of servers because poetry defeated AI models. It succeeded because vulnerable services were reachable, valuable compute was sitting behind them, and infected machines could be recycled into the next wave of scanning.
That distinction matters. The unusual C2 technique is new; the defensive lesson is familiar. Know what is exposed, patch it quickly, restrict what does not need public access, and monitor the expensive compute that attackers have every financial incentive to steal.
BitcoinVersus.Tech Editor’s Note: PoeLLM is the malware family; Canto Incognito is Black Lotus Labs’ name for the campaign. The reported 3,400 figure refers to victim servers observed over the campaign, not 3,400 confirmed organizations.
Follow BitcoinVersus.Tech on X for cybersecurity, AI infrastructure, Linux, networking, Bitcoin mining, and data-center reporting.
Support independent technology reporting: Bitcoin donations help fund BitcoinVersus.Tech research and publishing.
Disclaimer: BitcoinVersus.Tech provides technology news and analysis for informational purposes only.

Leave a Reply