cd /news/ai-safety/cryptomining-botnet-hides-c2-address… · home › topics › ai-safety › article
[ARTICLE · art-147490] src=helpnetsecurity.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers

Black Lotus Labs reported that a cryptomining botnet campaign it calls Canto Incognito, using malware dubbed PoeLLM, has infected more than 3,400 servers by breaking into exposed AI services and open-source tools and hiding its command-and-control addresses in a poem posted on GitHub. The researchers attribute the campaign to an Italian-speaking threat actor, and say the infected servers mine cryptocurrency and are used to hunt for new victims.

by read1 min views2 publishedOct 8, 2026

Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The malware reading it, dubbed PoeLLM, breaks into exposed AI services and open-source tools, mines cryptocurrency on them and uses them to hunt for new victims. The researchers call the campaign Canto Incognito and believe it is the work of an Italian-speaking threat actor who appears to be in it … More

The post Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers appeared first on Help Net Security.

── more in #ai-safety 4 stories · sorted by recency
── more on @black lotus labs 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/cryptomining-botnet-…] indexed:0 read:1min 2026-10-08 · —