Infected servers are being repurposed as scanning nodes that actively hunt for other vulnerable LiteLLM and Ollama instances to facilitate exponential botnet growth. The sudden pivot of cybercriminal organizations toward artificial intelligence infrastructure marks a significant turning point in the landscape of digital exploitation as 2026 progresses. Security analysts recently uncovered a sophisticated operation known as Canto Incognito, which centers on a highly specialized piece of malware dubbed PoeLLM. Unlike previous generations of botnets that sought any available processor to mine low-value tokens, this current threat is surgical, specifically hunting for the high-density GPU and CPU environments that power modern large language models. The campaign illustrates a dangerous intersection where the rapid, often disorganized, adoption of enterprise AI meets the predatory efficiency of veteran threat actors. Organizations across the globe are finding that the very tools they deployed to increase productivity are being silently transformed into illicit revenue streams for anonymous adversaries. This shift highlights a critical vulnerability in the modern software stack, where the speed of innovation continues to outpace the fundamental requirements of basic network hygiene.
The Innovation: Stealth and Targeted Systems
Creative Hiding: Technical Evasion via Public Repositories
The defining characteristic of the PoeLLM malware is its unconventional method for receiving operational instructions through a dead drop resolver hosted on GitHub. Conventional malicious software typically utilizes hardcoded IP addresses or Domain Generation Algorithms, both of which are susceptible to blocklisting, sinkholing, or seizure by law enforcement. In contrast, PoeLLM eschews these vulnerable methods in favor of a repository under the pseudonym ejejejdfbbebe, where the attacker has posted a seemingly harmless poem. The malware is programmed to parse this text, extracting specific keys associated with certain words or stanzas to derive the current IP address of its command-and-control server. This technique offers several tactical advantages, most notably the exploitation of high-reputation hosting services. Because the traffic is directed at a trusted platform like GitHub, automated security tools are unlikely to flag the connection as suspicious, allowing the botnet to maintain a persistent link to its handlers without triggering standard firewall alerts.
The attacker can rotate the entire command-and-control infrastructure by simply editing a few words in the hosted poem, a process that has already occurred at least eleven times since the campaign began. This dynamic rotation ensures that even if one server is identified and taken down, the botnet can be seamlessly repointed to a new location without requiring any changes to the malware’s code or URL structure. To a casual observer or a basic text-scanning algorithm, the repository looks like nothing more than a personal creative writing project, lacking the typical signatures of malicious configuration files or binary data. This level of human mimicry represents a sophisticated layer of obfuscation that challenges traditional signature-based detection systems. By blending in with legitimate developer activity, the Canto Incognito campaign has maintained a low profile while simultaneously scaling its operations to compromise thousands of high-value targets across the Western hemisphere, particularly in regions where AI research and development are most prevalent.
Vulnerability Vectors: Exploiting the Modern AI Stack
The current security vacuum is largely a byproduct of the rush to implement tools like LiteLLM and Ollama, which have become central to the AI ecosystem. LiteLLM acts as a gateway to manage various large language model providers, while Ollama serves as a standard for running models locally. The PoeLLM malware specifically targets instances where these tools are exposed to the internet without proper authentication protocols. By capitalizing on these misconfigurations, attackers can hijack the immense processing power required to run modern AI models, effectively turning expensive enterprise hardware into a private mining farm. The focus on compute-rich environments is a strategic move, as the high-performance GPUs utilized for model inference are also exceptionally efficient at solving the cryptographic puzzles required for mining. This makes AI servers far more profitable than traditional web servers or office workstations, leading to a concentrated wave of attacks on research labs and innovation hubs.
Beyond AI-specific tools, the campaign demonstrates a more aggressive tier of exploitation by targeting developer platforms like Gitea and document conversion APIs such as Gotenberg. The inclusion of a perfect score CVSS 10.0 vulnerability in Ivanti Sentry, known as CVE-2026-10520, reveals that the attackers are not merely looking for easy misconfigurations but are also capable of utilizing high-impact OS command injection flaws. This specific vulnerability allows unauthenticated remote attackers to execute commands with root privileges, providing a direct path to the core of enterprise network infrastructure. By integrating such a powerful exploit into their workflow, the operators behind PoeLLM can move beyond simple model runners and compromise hardened gateway appliances. This multi-pronged approach ensures that if a target lacks an exposed AI interface, the malware can still find a foothold through secondary developer services or unpatched enterprise software, creating a comprehensive threat profile for any modern organization.
Execution: Monetization and Global Attribution
The Mechanics: Cryptojacking and Botnet Expansion
Once PoeLLM establishes its presence on a compromised host, its primary objective shifts to the deployment of cryptocurrency mining software. The malware utilizes a dual-miner strategy, often deploying the XMRig miner to focus on Monero, a currency favored by cybercriminals due to its extreme privacy features. Monero transactions are notoriously difficult to trace, allowing the attackers to move their illicit earnings through various exchanges with minimal risk of detection by financial authorities. The use of a secondary miner further suggests that the attackers are optimizing their resource usage, switching between different algorithms depending on the specific hardware capabilities of the infected server. This ensures that whether a server is CPU-heavy or GPU-heavy, every available cycle is squeezed for maximum financial gain. The stolen compute power is then funneled into the Kryptex mining pool, a commercial service that simplifies the payout process while adding another layer of separation between the stolen resources and the attacker’s wallet.
The monetization of these servers is supplemented by a worm-like propagation mechanism that ensures the botnet remains self-sustaining. Infected hosts do not sit idly by while they mine; they are immediately repurposed as scanning nodes that actively probe the internet for other vulnerable instances of LiteLLM, Ollama, and Gitea. This creates an exponential growth loop where each new victim contributes to the further expansion of the network. The scanning activity is distributed, making it much harder for security teams to identify the original source of the attack, as the probes come from thousands of different legitimate but compromised enterprise IPs. This decentralized approach to expansion has allowed the Canto Incognito campaign to compromise more than 3,400 servers in a relatively short timeframe. By turning the victims’ own infrastructure against the rest of the internet, the PoeLLM operators have built a resilient and highly profitable operation that continues to thrive on the resource-intensive nature of the current AI boom.
Investigating the Origins: Clues and Historical Evolution
Investigative findings from network flow analysis and code reviews have provided several clues regarding the possible origins of the PoeLLM operators, though attribution remains a complex task. Researchers have identified various Italian-language strings within the malware’s source code and the comments on the GitHub repository used for the dead drop resolver. Furthermore, traffic patterns associated with the command-and-control infrastructure show significant activity and origin points within Italian network segments. While these factors suggest a Mediterranean origin for the campaign, security experts maintain a cautious stance, noting that these indicators could easily be false flags designed to misdirect investigators toward a specific geographic region. The consensus currently leans toward the campaign being the work of a financially motivated criminal group rather than a state-sponsored espionage unit, as the primary goal appears to be the accumulation of wealth rather than the theft of intellectual property.
To fully understand the threat posed by PoeLLM, one must view it as the latest stage in the evolution of cloud-based botnets. In previous years, the Kinsing botnet dominated the landscape by targeting exposed Docker and Kubernetes APIs for similar cryptomining purposes. PoeLLM represents the 2026 iteration of this trend, shifting its focus from general container orchestration to the specialized field of AI gateways. The underlying problem remains the same: the rush to implement new and powerful technology often leaves security as an afterthought. Just as developers previously left Docker daemons open to the public, the current wave of AI enthusiasts is leaving model runners exposed. This historical pattern confirms that as long as high-performance hardware is connected to the internet with default or non-existent security settings, threat actors will continue to adapt their tools to exploit those resources. The PoeLLM campaign is a stark reminder that the tools change, but the fundamental vulnerabilities of human error and rapid deployment remain constant.
Strategic Impact: Future Outlook and Industry Response
Market Shifts: Industry Consequences and Protective Measures
The emergence of the Canto Incognito campaign has sent ripples through the technology sector, forcing a reevaluation of how AI tools are deployed and managed. It has become increasingly clear that the default-to-open philosophy prevalent in many open-source projects is a significant liability for enterprise security. In response, there is a growing movement toward secure-by-default configurations, where authentication and network restrictions are mandatory rather than optional features. Organizations are beginning to demand more rigorous security certifications from AI tool vendors, and the procurement process is shifting to favor platforms that integrate seamlessly with existing identity and access management systems. This change is not just about preventing cryptojacking; it is about protecting the overall integrity of the AI models and the sensitive data they process. As the cost of a compromise now includes both massive energy bills and potential hardware damage from prolonged high-intensity mining, the financial incentive for better security has never been higher.
Cyber insurance providers are also playing a crucial role in shaping the industry response to this threat. Given the rising frequency of cryptojacking incidents targeting high-performance compute clusters, insurers are starting to mandate specific security scans and configurations as a prerequisite for coverage. Organizations that cannot demonstrate proper network segmentation and egress monitoring may find themselves ineligible for policies or facing significantly higher premiums. This economic pressure is driving a more disciplined approach to infrastructure management, where AI runners are treated as critical assets rather than experimental side projects. Effective mitigation now requires a combination of strict network policies, such as ensuring that tools like Ollama are never exposed directly to the public web, and the implementation of robust monitoring to detect outbound connections to known mining pools or unauthorized GitHub repositories. By treating AI security as a core business function, companies can better defend against the opportunistic nature of botnets like PoeLLM.
Future Roadmap: Actions Taken and Ongoing Defense
The technical community responded to the PoeLLM threat by developing more sophisticated asset discovery tools that specifically hunt for shadow AI instances within corporate networks. Security teams identified that employees were often setting up their own model runners to bypass official IT delays, unintentionally creating numerous entry points for the botnet. To counter this, many enterprises implemented strict egress filtering and established central, authenticated AI gateways that provide the necessary compute power without the associated risks of unmanaged local installations. These actions were paired with a renewed focus on patch management, particularly for gateway appliances that were previously overlooked. The discovery of the poem-based command-and-control mechanism also led to the creation of new behavioral analysis rules that look for unusual patterns of interaction with public code repositories, effectively closing the gap that the attackers had so effectively exploited during the initial phases of the campaign.
The overall security posture across the industry matured as organizations recognized the long-term implications of resource hijacking in the age of artificial intelligence. Law enforcement and cybersecurity agencies collaborated to monitor the Kryptex mining pool and other similar services, leading to the eventual identification and dismantling of several key C2 servers associated with the Canto Incognito operation. This coordinated response demonstrated that while the attackers were innovative, the collective defense of the security community was capable of adapting to these new tactics. The incident served as a definitive case study in the importance of maintaining basic security hygiene even when deploying the most advanced technology. By documenting the lifecycle of the PoeLLM malware and sharing the indicators of compromise, researchers ensured that the lessons learned from this campaign were integrated into future defense strategies, ultimately making the AI infrastructure of the future more resilient against the next generation of predatory software.
