← Back to stories
Security

Cryptomining malware used poetry to infect more than 3,400 servers, researchers say

Over 3,400 “victim servers” were hit by cryptomining malware PoeLLM during a campaign named Canto Incognito, tracked since April 2026, Lumen’s cybersecurity research team Black Lotus Labs reports. The malware’s “command-and-control (C2) mechanism” used address encoding through four words in a two-stanza poem on GitHub, altered 11 times so far, to direct affected hosts to new C2 servers. Most of those hit look to be running “vulnerable versions of open-source AI/LLM services, such as LiteLLM and Ollama,” despite an April LiteLLM fix that probably patched the exploitation path.

The malware’s payload consists of XMRig and Iron miners, connected to Kryptex mining infrastructure, with infected servers becoming scanners and exploit servers. The “primary commonality amongst the first 900 victims” was contact with “an endpoint for the Russian crypto mining service,” Lumen says. This indicates that it may be financially motivated. “AI infrastructure is becoming an attractive target” because exposed AI services may contain valuable data and hardware access, especially GPUs. …

You're reading a preview. The full article is published by Tom's Hardware on their website.

Read the full story on Tom's Hardware