A Poem as a Lookup Table
PoeLLM extracts its C2 server address from a poem titled “On the Nature of Connection.” The poem sits inside a file named dash.css, buried within a GitHub repository belonging to a user called “ejejejdfbbebe,” itself a fork of the nodejs.org website.
The malware pulls four specific words from the poem and converts them into numerical values using a hard-coded dictionary. Those four numbers become the C2 server’s IPv4 address. An earlier version, for example, translated “driver,” “diode,” “decryption,” and “string” into 92, 119, 165, and 74, assembling the address 92.119.165.74.
To move the botnet to a new server, the attacker simply edits four words in a public GitHub file. No suspicious domain registrations, no flagged IP ranges tied to known infrastructure, just a quiet commit to a repository that looks like forgettable open-source noise. That edit has happened 11 times since April 13, 2026.
Who’s Been Hit
The Canto Incognito campaign has been running since April 2026 and has compromised more than 3,400 servers globally, with most victims located in the US and Western Europe. Black Lotus Labs attributes the operation to an Italian-speaking threat actor, with financial gain as the apparent motive.
Researchers first stumbled onto PoeLLM while investigating an unrelated Ivanti Sentry vulnerability (CVE-2026-10520). The trail led to attackers specifically targeting vulnerable versions of open-source AI and LLM services, including LiteLLM and Ollama.
Hundreds of affected servers were also running Gotenberg, an open-source PDF converter, and Gitea, a software development toolkit. Attackers appear to have identified internet-exposed AI implementations as high-value targets, since they double as both intelligence sources and known vulnerability surfaces. The malware exploits flaws like CVE-2026-42271, a command injection bug in LiteLLM, to instruct compromised servers to download malicious payloads.
What the Malware Does Once Inside
Once installed, PoeLLM deploys XMRig and Iron cryptocurrency miners, connecting infected servers to the Russian Kryptex mining pool. Beyond mining, the malware carries a remote shell, HTTP/S scanning capability, and the ability to deploy further exploits.
Infected servers don’t stay passive. They actively scan for and exploit new targets, which is how the botnet keeps growing on its own. Recent activity shows bots probing SSH ports and other login portals, a pattern that suggests the operator may be building toward distributed brute-force attacks.
Current Status
Black Lotus Labs has blocked traffic to and from the known PoeLLM C2 servers and continues monitoring for new activity. The firm frames the campaign as part of a broader pattern: attack surfaces are expanding faster than AI infrastructure security is catching up.
“Incorporating AI tools into attack surface management and patch and update cycles is critical not only to protect enterprises from abuse of token usage and cryptomining, as evidenced in this campaign, but more critically from data loss, LLM jacking and lateral movement,” Black Lotus Labs researchers concluded.
Hashlytics Take
The poem trick is the real story here, not the server count. Security tools are built to flag known-bad IPs, suspicious domains, and infrastructure patterns, none of which apply to a text file sitting in a forked GitHub repo. That’s the part worth remembering past this specific campaign: as defenders get better at blocklisting infrastructure, attackers are shifting toward hiding instructions in places that look like noise rather than signal. Expect more C2 schemes that lean on legitimate platforms as cover, not because GitHub is uniquely exploitable, but because anywhere developers already trust becomes a blind spot by default.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



