MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-11 · via Tom's Hardware

Poetry-Based Malware Campaign Infects Thousands of Servers for Cryptomining

Image via Tom's Hardware
Image via Tom's Hardware

Lumen's Black Lotus Labs says a cryptomining malware campaign called Canto Incognito has compromised more than 3,400 servers since April 2026. The malware used four words in a two-stanza GitHub poem, changed 11 times, to point infected machines to new control servers. Many victims ran exposed AI/LLM services such as LiteLLM and Ollama, and the payload included XMRig and Iron miners.

Expanded Detail

Lumen’s Black Lotus Labs has tracked Canto Incognito since April 2026. It compromised more than 3,400 servers. The botnet’s control addresses were hidden in a GitHub poem, “On the Nature of Connection.” Four words across two stanzas encoded an IPv4 address; the poem changed 11 times to redirect infected hosts. Many victims ran exposed AI/LLM services, including LiteLLM and Ollama. A LiteLLM bug fixed in April was the likely entry point.

The payload used XMRig and Iron miners linked to Kryptex. Infected servers became scanners and exploit hosts. Early victims contacted a Russian crypto-mining endpoint, pointing to financial motives. Other targets included Gotenberg, Gitea, and possibly Ivanti Sentry. Lumen blocked traffic to and from the PoeLLM command servers.

Context

The campaign could affect organizations running internet-facing AI and developer tools, potentially exposing data, GPU capacity, and network resources. Infected systems may be conscripted into cryptomining and scanning, raising costs and disrupting services. Because exposed AI services can hold sensitive prompts or model access, victims may face privacy and operational risks. The incident may push operators to patch promptly, restrict public access, and monitor for unusual outbound traffic.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Tom's Hardware →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Cryptomining malware used poetry to infect more than 3,400 servers, researchers say.” Browse more stories.