The Canto Incognito campaign utilizes a dual-miner approach to diversify its exploitation of server hardware while funneling payouts through the Kryptex mining pool. This sophisticated operation, first identified by security researchers in late 2026, has highlighted a significant shift in the cybercrime landscape, moving away from simple data exfiltration toward the systematic hijacking of high-performance artificial intelligence infrastructure. By specifically targeting the massive computational resources required to host and run large language models, the perpetrators have identified a highly lucrative niche that traditional security protocols often fail to protect effectively. The campaign is not merely a random series of attacks but a coordinated effort to capitalize on the modern technological rush, where the speed of AI deployment frequently outpaces the implementation of rigorous defensive measures. As organizations worldwide integrate self-hosted AI gateways and model runners into their primary operations, they inadvertently create a vast, high-value attack surface that is uniquely attractive for unauthorized cryptocurrency mining operations.
The Canto Incognito Campaign: A New Frontier in Resource Theft
The discovery of the Canto Incognito campaign by Black Lotus Labs in October 2026 signaled the arrival of a more refined class of malware specifically engineered for the contemporary cloud ecosystem. Unlike previous generations of botnets that sought to infect as many personal computers as possible, the PoeLLM malware at the heart of this campaign focuses on high-density compute environments, such as those found in corporate research labs and specialized data centers. This strategic targeting ensures that each compromised node provides a significantly higher hash rate for mining operations, making the campaign far more efficient than broad-spectrum attacks on consumer-grade hardware. Since its initial emergence in April 2026, the campaign has shown a remarkable ability to adapt, with infection rates seeing a massive surge during the mid-months of the current year. This growth trajectory suggests that the operators are continuously refining their scanning techniques and exploitation payloads to keep pace with the rapid adoption of AI services globally.
The Silent Intrusion: Identifying the PoeLLM Botnet Architecture
At its core, PoeLLM represents a significant evolution in botnet design, functioning as a multi-stage, self-propagating threat that prioritizes stealth and long-term persistence. The malware architecture is built to operate within Linux-based environments, which are the standard for modern AI and developer operations, allowing it to blend in with legitimate system processes and administrative tools. Once the malware gains initial access to a host, it immediately begins a series of automated discovery routines to map the local environment and identify available hardware resources, particularly looking for powerful Graphics Processing Units that are essential for profitable mining. The sophistication of PoeLLM is evident in its modular approach, which allows the operators to update specific components of the botnet without needing to re-infect the entire network of compromised servers. This modularity, combined with its ability to spread autonomously across internal networks, makes it a formidable challenge for traditional security operations centers that may not be configured to monitor for AI-specific resource anomalies.
The GitHub Repository: Hiding in Plain Sight with Creative Writing
The most striking innovation found within the PoeLLM framework is its unconventional method of receiving instructions from its command-and-control operators via a public GitHub repository. Instead of using suspicious domains or hardcoded IP addresses that could be easily flagged by threat intelligence feeds, the attackers created a repository under a pseudonymous account and posted a seemingly innocuous poem. This creative writing project serves as a “dead drop resolver,” a tactic where the malware connects to a legitimate, high-reputation site to find its hidden configuration data. Because traffic to GitHub is a daily occurrence for developers and automated CI/CD pipelines, security tools are significantly less likely to block or even inspect these connections. This method effectively masks the malware’s communication within a sea of legitimate developer activity, allowing the botnet to remain undetected for extended periods. By leveraging the inherent trust associated with established developer platforms, the campaign has successfully bypassed the perimeter defenses of thousands of organizations.
The Dead Drop Resolver: How Malware Extracts Instructions from Poetry
The technical implementation of the PoeLLM dead drop resolver demonstrates a high degree of ingenuity in how it parses text to derive operational data. The malware is programmed to scan the stanzas of the poem hosted on GitHub, searching for specific linguistic markers or keys that correspond to the encrypted IP address of its actual command-and-control server. By using this indirect method, the attackers can rotate their backend infrastructure as often as necessary by simply editing a few words in the poem, without ever changing the URL the malware visits. Throughout the current year, researchers observed at least eleven distinct revisions to the repository, each one seamlessly repointing the entire botnet to new infrastructure to avoid localized takedowns or IP blocklisting. This dynamic rotation capability ensures that even if one server is identified and neutralized, the rest of the infected network can be quickly updated to reconnect with a different point of contact. This technique effectively turns a simple creative writing project into a robust, censorship-resistant control mechanism for a global network of hijacked servers.
Targeting the Innovation Stack: The Exploitation of AI Model Runners
The Canto Incognito campaign specifically focuses its efforts on a security vacuum created by the rapid adoption of specialized AI software and developer tools. As organizations have rushed to implement local versions of large language models to ensure data privacy or reduce latency, many have neglected the fundamental security hygiene required for internet-facing services. The malware purposefully hunts for instances of LiteLLM, a popular gateway used to manage multiple model providers, and Ollama, the industry standard for running AI models locally. These tools are often deployed by developers seeking quick experimentation, leading to configurations where the software is exposed to the public internet without any form of authentication or robust access control. The attackers recognize that these specific applications are always linked to the most powerful hardware in an organization’s inventory. By hijacking an AI runner, they gain access to high-end hardware that is specifically optimized for the types of mathematical calculations required for both artificial intelligence and cryptocurrency mining.
Specific Tooling Risks: Vulnerabilities in LiteLLM and Ollama
The focus on LiteLLM and Ollama reveals a calculated understanding of the modern developer workflow and the specific points where security is most likely to be overlooked. In many documented cases of infection, the servers were compromised not because of complex zero-day exploits, but because of simple misconfigurations where administrative ports were left open to the world. This allowed the PoeLLM malware to issue direct commands to the AI services, essentially using the tools’ own functionality to download and execute the malicious mining payload. Furthermore, the targeting of Gitea, a lightweight Git service, and Gotenberg, a document conversion API, suggests that the attackers are also interested in the broader developer infrastructure that surrounds AI projects. These services often serve as entry points into internal networks or contain sensitive source code that could be leveraged for further exploitation. The synthesis of these targets creates a comprehensive strategy for infiltrating the “compute-rich” environments of modern innovation hubs, where the hardware is fast and the oversight is often minimal.
Beyond Misconfiguration: Leveraging the Ivanti Sentry Critical Flaw
While many infections in the Canto Incognito campaign stem from improperly secured AI tools, the attackers have also demonstrated a willingness to use more aggressive exploitation methods when necessary. A key component of the campaign’s success was the integration of a critical vulnerability in Ivanti Sentry, known as CVE-2026-10520, which allowed for unauthenticated remote command injection. This specific exploit provided the attackers with a “perfect score” entry point into hardened enterprise environments that might have otherwise been protected by perimeter security appliances. By utilizing this vulnerability, the PoeLLM operators were able to gain root privileges on gateway devices, allowing them to bypass firewalls and deploy their malware directly onto internal high-performance servers. This multi-tiered approach—targeting both simple misconfigurations and high-severity vulnerabilities—shows a level of tactical flexibility that is characteristic of modern, professional cybercrime groups. It ensures that the botnet can continue to grow even as the most obvious security gaps in the AI industry are eventually closed.
The Monetization Engine: Dual-Miner Tactics and Cryptojacking Goals
Once a server has been successfully compromised, the PoeLLM malware initiates its primary objective: the continuous generation of revenue through unauthorized cryptocurrency mining. To maximize the utility of the stolen hardware, the malware employs a dual-miner approach, deploying both the ubiquitous XMRig software and a secondary miner known as Iron. This strategy allows the botnet to diversify its operations, utilizing XMRig for standard CPU mining while the secondary miner targets specific algorithmic opportunities that might arise on more specialized server hardware. The choice of Monero as the primary currency for these operations is a deliberate move based on its privacy-centric features, which make it exceptionally difficult for law enforcement or financial institutions to trace the movement of the illicitly earned funds. This focus on anonymity ensures that the perpetrators can maintain a steady stream of income without fear of their digital wallets being blacklisted or their identities being revealed through public blockchain analysis.
Strategic Obfuscation: Utilizing Kryptex and Monero for Anonymity
The monetization strategy of the Canto Incognito campaign is further enhanced by the use of the Kryptex mining pool, a professional service that simplifies the process of converting raw hashing power into liquid assets. By funneling the collective output of over 3,400 infected servers into a commercial pool, the attackers add a significant layer of obfuscation between the compromised hardware and their personal finances. The mining pool acts as a buffer, making it appear to an outside observer that the traffic is simply coming from a large, legitimate mining participant. This use of legitimate services for illegitimate ends is a recurring theme throughout the campaign, from the GitHub “dead drop” to the Kryptex payout system. This approach not only streamlines the technical aspects of the mining operation but also reduces the likelihood of the payout addresses being flagged as malicious. It represents a mature understanding of how to operate within the existing financial and technological ecosystems without raising the alarms that typically follow more disruptive forms of cybercrime.
The Self-Sustaining Loop: Worm-Like Propagation and Global Scanning
A defining characteristic of the PoeLLM malware that has contributed to its rapid spread throughout the year is its sophisticated self-propagation mechanism. Every infected host is not merely a silent miner but is repurposed as an active scanning node that tirelessly searches the internet for other vulnerable targets. These compromised servers are programmed to look for the specific open ports associated with LiteLLM, Ollama, and Gitea, creating a self-sustaining growth loop that expands the botnet exponentially without requiring the primary operators to launch new attacks from their own infrastructure. This decentralized approach to growth makes the botnet incredibly resilient; even if the original command-and-control server is taken down, the thousands of scanning nodes continue to look for new victims. The worm-like behavior ensures that the campaign can capitalize on the global expansion of AI services in real-time, instantly identifying and infecting new servers as soon as they are brought online with insecure configurations.
Forensic Analysis: Tracing the Italian Connection and Source Code
Investigations into the Canto Incognito operation have yielded several intriguing clues regarding the potential origins of the threat actors involved. Forensic analysis of the PoeLLM source code revealed the presence of specific Italian-language strings and comments, suggesting that at least some of the developers or operators may be based in Italy or have a strong connection to the region. This assessment was further supported by netflow analysis, which showed significant command-and-control activity originating from and passing through Italian network infrastructure. However, security experts have maintained a level of caution, noting that these indicators could easily be “false flags” designed to divert attention toward a specific geographic area and away from the true perpetrators. Regardless of the actual physical location of the attackers, the consensus among the cybersecurity community is that the operation is purely financially motivated, lacking the typical hallmarks of state-sponsored espionage or politically driven disruption.
Lessons from the Past: Comparing PoeLLM to the Kinsing Malware
The emergence of PoeLLM is best understood as the modern successor to earlier cloud-based cryptojacking threats, most notably the Kinsing botnet that plagued the industry for years. Just as Kinsing achieved success by scanning for exposed Docker and Kubernetes APIs during the height of the containerization movement, PoeLLM has adapted that proven model for the AI era. The fundamental strategy remains identical: identify a rapidly growing technology trend where security is often an afterthought and exploit the resulting misconfigurations to steal raw compute power. The transition from general-purpose cloud containers to specialized AI gateways reflects the changing nature of the infrastructure that organizations find most valuable. PoeLLM simply recognizes that in the current market, the highest concentration of high-end hardware is no longer in general web servers but in the specialized clusters built to handle large language models and other AI-driven workloads. This historical continuity proves that while the specific software targets may change, the underlying patterns of exploitation remain remarkably consistent.
Future-Proofing Infrastructure: Actionable Security Measures for 2026
The investigation into the PoeLLM malware and its widespread impact throughout the current year demonstrated a critical need for a fundamental reset in how AI infrastructure is managed. Administrators found that the most effective defense was not the implementation of complex new tools but the rigorous application of existing security principles to new software stacks. The campaign proved that leaving AI gateways and model runners directly exposed to the public internet without authentication was a catastrophic risk that modern botnets were prepared to exploit within minutes. Organizations that successfully mitigated the threat were those that moved their AI services behind robust identity and access management systems and strictly enforced network segmentation. Furthermore, the incident highlighted the importance of monitoring for unusual outbound connections to raw content hosting sites like GitHub, which served as the primary command link for the botnet. Moving forward, the industry learned that the “rush to innovate” must be balanced with automated asset discovery to ensure that “Shadow AI” instances do not become the weak link in an otherwise hardened enterprise network.

