PoeLLM Botnet Hides C2 Addresses in GitHub Poetry to Hijack AI Servers
A sophisticated cryptomining botnet dubbed PoeLLM has quietly compromised more than 3,400 internet-exposed AI service servers since April 2026, using an remarkably creative technique to hide its command-and-control infrastructure: a poem posted on GitHub.
Researchers at Lumen Technologies’ Black Lotus Labs uncovered the campaign, which they named Canto Incognito. The operation, attributed to an Italian-speaking financially motivated threat actor, represents a new frontier in malware ingenuity — weaponizing creative writing to evade detection and takedown efforts.
How the GitHub Poem C2 Mechanism Works
The malware’s command-and-control address is concealed within a seemingly innocuous poem published on GitHub. PoeLLM extracts four specific words from fixed positions in the poem and matches each word to a number using a dictionary hardcoded into the malware. Those four numbers form the IPv4 address of the current C2 server.
In one earlier version of the poem, the words driver, diode, decryption, and string translated to the numbers 92, 119, 165, and 74 — yielding the C2 address 92.119.165.74. When the attacker needs to rotate infrastructure, they simply change those four words in the GitHub repository, and every infected machine automatically calculates the new address on its own.
The poem has been edited 11 times since the first commit on April 13, 2026. Each edit redirected victims to a new C2 server. This approach makes conventional IP-blocking countermeasures nearly useless — the attacker needs only a few word changes to re-establish connectivity across the entire botnet.
Targets and Attack Vector
The majority of victims are running vulnerable versions of open-source AI and large language model services. The primary targets include:
- LiteLLM — an AI model gateway with a command injection vulnerability (CVE-2026-42271) in its
/mcp-rest/test/connectionendpoint - Ollama — a local LLM runtime
- Gotenberg — an open-source PDF conversion tool
- Gitea — a software development platform
- Ivanti Sentry — compromised via CVE-2026-10520
The attacker scanned the internet primarily for ports 3000 and 4000, the default ports for Gotenberg and LiteLLM respectively. When a vulnerable server was identified, an exploit server delivered a crafted POST request instructing the target to download malware from the C2 server. Most victims are located in the United States and Western Europe.
What the Malware Does Once Installed
Once a server is compromised, PoeLLM deploys multiple payloads:
- Cryptocurrency mining — Runs the XMRig and Iron cryptocurrency miners, connecting victims to the Russian Kryptex mining pool
- Credential theft — Extracts API credentials for major AI providers including OpenAI, Anthropic, AWS Bedrock, and Azure
- Remote shell access — Provides the attacker with interactive command execution on infected hosts
- Scanning and exploitation — Enlists victim servers to scan for and exploit new targets, growing the botnet automatically
- Brute-force capabilities — More recently, bot groups began targeting SSH ports and login portals, suggesting distributed brute-force attacks are under development
Infected servers become unwilling participants in the botnet’s expansion. Each compromised machine is put to work scanning for new vulnerable services, creating a self-propagating infection chain that has operated undetected for over five months.
The Broader AI Infrastructure Threat
The Canto Incognito campaign highlights a growing concern in the cybersecurity landscape: AI service infrastructure is increasingly under attack. As organizations rush to deploy AI tools, many expose management interfaces and APIs to the internet without adequate security controls.
The stolen API credentials create secondary damage beyond cryptomining. Attackers can misuse AI provider credentials for:
- LLM jacking — Unauthorized use of AI models at the victim’s expense, generating substantial API costs
- Data exfiltration — Accessing sensitive prompts, training data, or model outputs stored on AI platforms
- Lateral movement — Using compromised credentials to pivot into cloud environments and production systems
Researchers noted that delays in updating vulnerable AI services create windows of opportunity that attackers exploit rapidly. The gap between vulnerability disclosure and patch deployment remains a critical weakness across the industry.
Detection and Mitigation Strategies
Organizations running AI service infrastructure should take immediate action to protect against PoeLLM and similar threats:
- Patch immediately — Upgrade LiteLLM to version 1.83.14-stable or later, and ensure all AI services are running current versions
- Restrict internet exposure — AI management interfaces should not be publicly accessible. Use firewalls, VPNs, or zero-trust network access to control connectivity
- Monitor API usage — Watch for anomalous API calls, unexpected cryptocurrency mining processes, or unusual outbound network traffic
- Audit credentials — If compromise is suspected, rotate all AI provider API keys, cloud credentials, and access tokens
- Deploy IOC matching — Black Lotus Labs has published indicators of compromise. Run these against firewall logs and network traffic monitors
- Monitor GitHub dependencies — Be aware that C2 infrastructure can hide in plain sight on legitimate platforms like GitHub
The Evolving Malware Landscape
The Canto Incognito campaign demonstrates how threat actors are adapting their techniques to target the AI infrastructure boom. The use of a GitHub-hosted poem as a C2 address book is particularly notable — it exploits the trust that security tools place in well-known developer platforms, making detection significantly harder.
Black Lotus Labs has stated it has blocked traffic to and from known PoeLLM C2 servers and will continue monitoring for new infrastructure. However, the poem-based C2 rotation mechanism means defenders must remain vigilant, as the attacker can re-establish communications with minimal effort.
As AI services become more deeply integrated into enterprise operations, the attack surface will only grow. Organizations must treat AI infrastructure with the same security rigor applied to traditional cloud services — or risk becoming the next node in a growing botnet that reads poetry to find its master.
Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous
Discover more from QUE.com
Subscribe to get the latest posts sent to your email.
