Over 3,400 “victim servers” were hit by cryptomining malware PoeLLM during a campaign named Canto Incognito, tracked since April 2026, Lumen’s cybersecurity research team Black Lotus Labs reports. The malware’s “command-and-control (C2) mechanism” used address encoding through four words in a two-stanza poem on GitHub, altered 11 times so far, to direct affected hosts to new C2 servers. Most of those hit look to be running “vulnerable versions of open-source AI/LLM services, such as LiteLLM and Ollama,” despite an April LiteLLM fix that probably patched the exploitation path.The malware’s payload consists of XMRig and Iron miners, connected to Kryptex mining infrastructure, with infected servers becoming scanners and exploit servers. The “primary commonality amongst the first 900 victims” was contact with “an endpoint for the Russian crypto mining service,” Lumen says. This indicates that it may be financially motivated. “AI infrastructure is becoming an attractive target” because exposed AI services may contain valuable data and hardware access, especially GPUs. In the meantime, it has “blocked all traffic to and from the PoeLLM C2 servers.”The primary targets are LiteLLM, a proxy server (AI Gateway) to call LLM APIs, a way companies can route their apps to many models through one endpoint, and Gotenberg, a Docker-based API for PDF conversion, which has a guide warning not to expose it to the internet. Also hit are Ollama, which allows you to run open-weight models on your own hardware, although it is not internet-exposed by default, and Gitea, a self-hosted Git platform. Ivanti Sentry, an enterprise gateway appliance, “may also have been targeted,” and one instance was how Lumen discovered the campaign.Although the malware’s methodology involves leveraging poetry, this is only for pointing the infected servers to the C2 server. It is not a form of an AI jailbreak through harmful requests or prompt injection, or what is known as “adversarial poetry,” described in a paper last year.The poem, “On the Nature of Connection,” was first committed in April, with each new version pointing to a new C2 server. The malware is able to decode the new address by pulling specific words and converting them into an IPv4 address. Lumen says that “the malware creator has not changed the pattern used in deciphering the poem” at the time of reporting. Using a poem likely aided in obfuscation as it is “a perfect vehicle for hiding an important message,” the researchers told The Register.The malware is “deployed through vulnerability exploitation of publicly exposed services,” with broad scanning beginning in May. For LiteLLM, a crafted POST to the connection endpoint “was likely the exploitation path,” based on a flaw where two endpoints would run a supplied command on the host with no role check (CVE-2026-42271), which CISA added to its list of exploited vulnerabilities in June. Lumen didn’t detail the methods for Ollama, Gotenberg, and Gitea.If you want to check your own systems, look at connection logs for the indicators of compromise listed on Lumen’s GitHub page. Be sure to audit external exposure when installing any open-source tool and close unnecessary ports. Patch any and all network devices. Follow the individual advisories for the vulnerable products — LiteLLM 1.83.7 or later and Ivanti Sentry R10.5.2, R10.6.2, or R10.7.1.When Lumen published its report, three of the 12 C2 servers were still active and the campaign “continues to infect new victims.” The firm “will continue to monitor for new traffic.” More attacks like this seem likely: Lumen says enterprise attack surfaces are “expanding rapidly as AI infrastructure grows.”