Summary
- Black Lotus Labs has identified more than 3,400 compromised servers since April.
- Targets include LiteLLM, Gotenberg, Gitea and other internet-facing services.
- Compromised hosts are reused to scan for and attack additional systems.
A malware campaign targeting exposed AI and developer infrastructure has compromised more than 3,400 servers since April, reusing infected systems to mine cryptocurrency and search for additional victims.
Researchers at Lumen Technologies Black Lotus Labs are tracking the malware as PoeLLM and the wider campaign as Canto Incognito. Victims are concentrated in the United States and Western Europe, with activity reaching almost 2,200 affected servers at its mid-June peak and nearly 800 systems active on some days.
The campaign targets enterprise services exposed to the internet, including LiteLLM, Gotenberg and Gitea, while researchers have also seen attempts involving Ivanti Sentry appliances. Compromise relies on exploitable internet-facing services rather than a weakness common to every AI platform.
Once access is gained, the attackers deploy cryptocurrency miners including XMRig and Iron. Some compromised machines are then converted into scanners and exploitation servers, allowing the botnet to search for additional vulnerable systems from infrastructure it has already captured.
That second function means an infected organisation can contribute to attacks against unrelated targets even when its most visible local symptom is resource consumption from cryptomining. Malicious traffic is distributed across compromised systems rather than originating solely from infrastructure directly operated by the attacker.
PoeLLM also uses an unusual method to locate its command-and-control infrastructure. The malware retrieves words from a poem stored in a GitHub repository and converts selected terms into an IP address through a dictionary embedded in the malware.
When the operators change the relevant words, the malware can derive a new command-and-control address without needing a conventional hard-coded domain or visible IP address in the hosted text. Researchers say the GitHub poem has been altered repeatedly as infrastructure changed.
The campaign’s target selection reflects a broader expansion in AI infrastructure exposed directly to the internet. Tools for serving models, routing requests or supporting development workflows can be deployed rapidly by engineering teams and may fall outside the inventory and change controls applied to established production services.
Compute capacity adds another incentive. Servers provisioned for AI workloads may offer substantial processing resources that can be converted into cryptocurrency mining once an attacker gains control, increasing their value even when the underlying application data is not the primary objective.
The security problem resembles earlier campaigns against databases, container management services and development tools left publicly reachable with exploitable software or weak access controls. AI changes the type of workload being targeted, but the underlying exposure remains rooted in internet accessibility, vulnerable services and incomplete asset ownership.
Black Lotus Labs attributes the operation to an Italian-speaking actor with moderate confidence, based on language artefacts and network-flow evidence. That assessment identifies characteristics of the operator rather than establishing state sponsorship or a broader political motive.
Recent activity also suggests experiments with distributed brute-force attempts against SSH and other login portals, although researchers say the maturity of that capability remains uncertain. Cryptomining and botnet expansion remain the better established uses of the compromised infrastructure.
The campaign demonstrates how AI servers are becoming part of the ordinary Linux attack surface. Organisations operating model and developer services inherit familiar requirements around software maintenance, authentication, exposure management and asset discovery even when the business use of the technology is new.





