MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-08 · via Help Net Security

Botnet uses GitHub poem to conceal command servers and mine crypto on exposed AI systems

Image via Help Net Security
Image via Help Net Security

Black Lotus Labs has detailed a campaign called Canto Incognito that has compromised more than 3,400 servers since April 2026. The malware, named PoeLLM, targets vulnerable open-source AI and large language model tools, then mines cryptocurrency and scans for additional victims. Its operators hide command-and-control addresses inside a poem hosted on GitHub, according to the researchers.

Expanded Detail

Black Lotus Labs traced Canto Incognito to April 2026. The operation has ensnared over 3,400 servers, largely in the US and Western Europe. PoeLLM exploits weak open-source AI/LLM deployments, including LiteLLM and Ollama, plus Gotenberg and Gitea. It also installs XMRig and Iron miners, links victims to Kryptex, and adds remote shell, scanning, and exploit tools.

The C2 address is encoded in a GitHub-hosted poem, "On the Nature of Connection," stored as dash.css in a repository forked from nodejs.org's source. Four fixed words map through a built-in dictionary to an IPv4 address. Eleven edits have redirected bots to new servers. Discovery began with an Ivanti Sentry flaw, CVE-2026-10520.

Context

Organizations running exposed AI/LLM, PDF conversion, and developer tooling may face stolen compute, higher cloud bills, service disruption, and use of their systems in further attacks. Because compromised machines scan and exploit others, the campaign could expand beyond initial victims, affecting downstream users and internet stability. The GitHub poem trick may complicate takedowns, as defenders must track changing encoded addresses.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Help Net Security →
Related stories
Canto Incognito Campaign Uses PoeLLM Malware to Build Crypto-Mining Botnet from AI Servers · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers.” Browse more stories.