PoeLLM is Linux cryptomining malware used in the financially motivated Canto Incognito campaign, active since at least April 2026. It compromises internet-facing AI infrastructure and other server applications, with victims running services including LiteLLM, Ollama, Gotenberg, and Gitea. Thousands of affected servers have been identified, primarily in the United States and Western Europe. The malware incorporates XMRig and Iron cryptocurrency miners, remote-shell functionality, HTTP/S scanning, and exploit deployment. Compromised servers provide computing resources for mining and become scanning and exploitation workers that identify and infect additional vulnerable systems. Observed activity includes attempts to exploit the LiteLLM command-injection vulnerability CVE-2026-42271.
PoeLLM discovers its command-and-control server by retrieving an attacker-controlled poem hosted in a GitHub repository. It extracts four words or phrases using fixed textual anchors and maps them through a hard-coded dictionary to numeric values forming an IPv4 address. Editing the poem allows the operator to redirect infected systems without updating the malware. This deterministic encoding conceals command-and-control information in otherwise innocuous text; it does not require an LLM during execution. The campaign's operator has not been conclusively identified or linked to an established threat group.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Once a server is compromised, it becomes a springboard to spread the malware further, using scanning on ports 3000 and 4000, associated with Gotenberg and LiteLLM, and attempting to exploit CVE-2026-42271. | A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware central to the financially motivated Canto Incognito campaign. It compromises internet-facing servers, particularly those running vulnerable LiteLLM and Ollama services, deploys cryptocurrency miners, and turns infected machines into vulnerability scanners and exploit servers to expand its botnet. It retrieves its C2 address by extracting four words from a poem hosted on GitHub and translating them into IPv4 octets using a hard-coded dictionary. Updating the poem redirects infected systems to new C2 infrastructure. Although the article calls this adversarial poetry, the described C2 mechanism uses deterministic parsing rather than an demonstrated LLM jailbreak. The malware was observed during an investigation into CVE-2026-10520, but the article does not explicitly establish that PoeLLM exploits that vulnerability.
Malware used in the financially motivated Canto Incognito campaign to compromise exposed AI/LLM infrastructure and other internet-facing services, deploy cryptocurrency miners, and expand a botnet. It derives its C2 address from words in a GitHub-hosted poem. Some infected servers become scanners and exploit servers that compromise additional systems. Activity dates to April 2026, with more than 3,400 victim servers identified, primarily in the U.S. and Western Europe. No specific exploited vulnerabilities are named.
Linux ELF malware distributed as a file named libgcrypt. It derives C2 IPv4 addresses from words in a GitHub-hosted poem using a hard-coded dictionary. It provides remote-shell access, incorporates XMRig and Iron cryptocurrency miners, and propagates through HTTP/S scanning and exploit deployment. Researchers report more than 3,400 compromised servers, primarily across the United States and Western Europe, with up to 800 active infections in one day. Targets include exposed AI services and development tools; propagation includes scanning ports 3000 and 4000 and attempting to exploit LiteLLM's CVE-2026-42271.
PoeLLM has compromised more than 3,400 servers since April, targeting open-source AI services and other exposed applications, including LiteLLM, Ollama, Gotenberg and Gitea. It supports exploit scanning, cryptocurrency mining and remote code execution, turning compromised servers into attack proxies. To discover its current command-and-control address, it retrieves a GitHub-hosted poem, extracts four words using fixed text anchors and maps them through an embedded dictionary to four IP-address octets. Changing the poem lets the operator rotate infrastructure without updating the malware. Potential AI-model abuse, credential theft and token abuse are described as risks, not confirmed observed activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.