
Canto Incognito Cryptomining Botnet Infects 3,400+ Servers Using PoeLLM Malware Hidden in GitHub Poem
AIbotnetGitHubmalwarecryptominingcybersecuritythreat-intelligence
Black Lotus Labs discovered a cryptomining botnet campaign called Canto Incognito that has infected over 3,400 servers using malware dubbed PoeLLM. The malware retrieves command and control server addresses hidden within a poem posted on GitHub. PoeLLM targets exposed AI services and open-source tools to mine cryptocurrency and propagate to additional victims. The researchers attribute the campaign to an Italian-speaking threat actor.