Inside Canto Incognito: 3400+ servers targeted by PoeLLM Malware for crypto mining

09 Oct 2026

Cybersecurity researchers at Lumen Black Lotus Labs have identified a campaign that involves PoeLLM malware. The campaign, named Canto Incognito, targets publicly exposed enterprise AI/LLM infrastructure.

 

Through our blog, we will understand what the Canto Incognito campaign is about, the threat it poses, and what organizations should do to defend against it.

About the vulnerability

Campaign/Targeted regions/country 

Threat type

Primary malware  

Threat Actor

Targeted technology 

Affected/Targeted Products 

Canto Incognito/ 

Western Europe/the United States 

 

Malware, Cryptojacking, Botnet Expansion and Exploitation of Internet-Facing Services 

 

PoeLLM 

Italian-speaking threat actor, attributed with moderate confidence 

 

Internet-facing AI/LLM infrastructure and enterprise applications 

The campaign has primarily been observed targeting internet-facing deployments and appliances, including: 

 

  • LiteLLM 
  • Gotenberg 
  • Gitea 
  • Ivanti Sentry 
  • Other publicly exposed services containing known exploitable weaknesses 

 

The campaign targets publicly exposed AI/LLM infrastructure, with an objective to compromise servers, deploy cryptocurrency miners, and use compromised systems to scan for and infect vulnerable hosts. Since April 2026, over 3,400 targeted servers have been identified.

Canto Incognito

What distinguishes PoeLLM malware is its C2 discovery mechanism. Instead of directly embedding the command-and-control address, it fetches a poem hosted on a GitHub repository and extracts four words from it. Lumen’s Black Lotus Labs have identified a two-stanza poem titled “On the Nature of Connection”, hosted on GitHub repository.

 

The malware maps these words to numbers using a hard-coded dictionary, combining them to construct the C2’s address. When the threat actor modifies the words to point to new C2 infrastructure, the infected systems can directly get the updated address without having to update the malware.

PoeLLM C2 Discovery Flow Infographic

How can it impact organizations?

The campaign particularly affects organizations with AI/LLM environments since they provide the computational resources that can be abused for cryptocurrency mining.

 

A successful compromise may allow threat actors to:

 

  • Deploy cryptocurrency miners such as XMRig and Iron.
  • Consume CPU and system resources for unauthorized cryptocurrency mining.
  • Convert compromised servers into internet scanners.
  • Use infected infrastructure to identify additional vulnerable systems.
  • Download and deploy malware onto newly identified targets.
  • Establish persistence and maintain control of compromised infrastructure.
  • Increase operational costs through excessive CPU, memory, and network consumption.
  • Potentially expose sensitive information hosted on compromised AI/LLM infrastructure.
  • Use compromised enterprise systems as infrastructure for further malicious activity.

Official security guidance

As the reported campaign targets vulnerable and publicly exposed services, organizations should:

 

  • Patch LiteLLM, Gotenberg, Gitea, Ivanti Sentry and other internet-facing applications to their latest vendor-supported versions.
  • Identify AI/LLM services and enterprise applications exposed directly to the internet.
  • Remove unnecessary public exposure of management and administrative interfaces.
  • Restrict access to AI/LLM services through VPN, private networking, access-control lists or other trusted access mechanisms where possible.
  • Review systems for unauthorized cryptocurrency-mining processes.
  • Monitor unexpected outbound connections from servers to unknown external infrastructure.
  • Investigate systems exhibiting unusual CPU utilization or persistent high resource consumption.
  • Review server processes, scheduled tasks, cron jobs and startup mechanisms for unauthorized persistence.
  • Monitor for unexpected HTTP POST requests and outbound connections associated with compromised systems.
  • Review firewall, proxy, DNS and EDR telemetry for suspicious outbound activity.
  • Rebuild or isolate systems where malware persistence or unauthorized modification is confirmed.

SharkStriker’s recommendations

SharkStriker recommends that organizations prioritize internet-facing AI/LLM and enterprise application assets as part of their vulnerability and threat-hunting activities.

 

Here’s what we recommend:

 

Identify exposed AI/LLM infrastructure

  • Maintain an inventory of publicly accessible LiteLLM, Gotenberg and other AI-related services.

 

Perform an external exposure review

  • Identify services that are directly reachable from the internet and determine whether public exposure is operationally required.

 

Patch exposed applications

  • Ensure all internet-facing applications and appliances are running the latest vendor-supported security releases.

 

Hunt for cryptocurrency miners

  • Look for unexpected processes such as xmrig, abnormal CPU utilization and processes executing from temporary or unusual directories.

 

Monitor outbound network activity

  • Investigate unusual connections from application servers to unknown external IP addresses, mining infrastructure or unexpected C2 destinations.

 

Monitor for lateral propagation

  • Since compromised servers may be converted into scanners, investigate unusual outbound scanning and repeated connection attempts against multiple external hosts.

 

Review process and persistence mechanisms

  • Check cron jobs, systemd services, startup scripts, scheduled tasks and newly created users for unauthorized modifications.

 

Strengthen server access controls

  • Restrict SSH and administrative interfaces to trusted networks and enforce strong authentication.

 

Deploy EDR / workload monitoring

  • Ensure critical AI/LLM and application servers are covered by appropriate endpoint or workload security monitoring.

 

Investigate resource anomalies

  • Unexpected sustained CPU consumption should be investigated as a potential cryptojacking indicator, particularly when the affected workload does not justify the resource usage.

Threat Hunting Focus

SOC teams should prioritize the following telemetry:

Endpoint / Server:

  • Unexpected xmrig or cryptocurrency-mining processes
  • High and sustained CPU utilization
  • Unknown binaries executing from /tmp, /var/tmp or other unusual locations
  • Newly created users
  • New cron jobs or systemd services
  • Unexpected startup scripts
  • Suspicious child processes spawned by web/application services

 

Monitor network for:

  • Outbound connections to unknown C2 infrastructure
  • Repeated outbound connections to multiple external IP addresses
  • Large-scale scanning activity originating from application servers
  • Unexpected HTTP POST requests
  • Connections to cryptocurrency-mining infrastructure
  • Abnormal outbound traffic from AI/LLM servers
  • Application / Web Logs:
  • Unexpected requests to exposed AI/LLM endpoints
  • Exploitation attempts against internet-facing applications
  • Suspicious POST requests
  • Requests originating from unusual geographic locations
  • Repeated requests from a single source against multiple application endpoints

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE