PoeLLM hits 3,400 servers mining on exposed LiteLLM and Ollama
Canto Incognito botnet hides its command server in a GitHub poem

PoeLLM hits 3,400 servers mining on exposed LiteLLM and Ollama

Lumen Black Lotus Labs reported on 7 October 2026 that a malware family it calls PoeLLM has compromised more than 3,400 servers since April. The campaign, named Canto Incognito, installs XMRig and Iron miners and points them at Kryptex. Infected hosts are then reused as scanners and exploit servers.

What happened

PoeLLM hides its command address in a poem the operators host on GitHub. The first commit was 13 April 2026. When they move the controller, they change a few words. The binary maps those words through a hard-coded dictionary to an IPv4 address. Lumen says the poem has been changed at least a dozen times.

The main targets are internet-facing LiteLLM and Ollama, plus Gotenberg, Gitea, and in some cases Ivanti Sentry. Researchers first saw the infrastructure in June while looking at Ivanti Sentry CVE-2026-10520. At the mid-June peak, almost 2,200 servers were affected and nearly 800 were active in a day. Infections concentrate in the United States and Western Europe. Newer traffic toward SSH and login portals looks like distributed brute force, and Lumen says that capability is not yet mature.

Lumen attributes the activity to an Italian-speaking actor with moderate confidence, based on language artifacts and netflow. The binary is an ELF named libgcrypt. It can run commands on the host, so a miner box can also be used to abuse models or pivot.

Who is affected

  • Internet-exposed LiteLLM proxies and Ollama instances with no authentication in front of them.
  • Exposed Gotenberg PDF converters and Gitea servers the same actor has been scanning.
  • Any GPU host that was stood up for an internal AI pilot and left reachable from the internet.

What to do now

Take LiteLLM, Ollama and similar AI gateways off the public internet, or put them behind authentication and an allowlist. Hunt for unexpected miners, outbound connections to mining pools, and a process named libgcrypt that is not the real library. Patch known flaws on anything the scanners are hitting, including Ivanti Sentry if you still run it. A compromised gateway is also a credential and prompt store, not only a stolen GPU.

Source: The Hacker News, citing Lumen Black Lotus Labs, PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-102255 CVSS 10.0 SSRF in SonicWall SMA1000 WorkPlace
Pre-auth SSRF on SMA1000 models 6210, 7210 and 8200v