Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers Black Lotus Labs reported that a cryptomining botnet campaign it calls Canto Incognito, using malware dubbed PoeLLM, has infected more than 3,400 servers by breaking into exposed AI services and open-source tools and hiding its command-and-control addresses in a poem posted on GitHub. The researchers attribute the campaign to an Italian-speaking threat actor, and say the infected servers mine cryptocurrency and are used to hunt for new victims. Thousands of hijacked servers have been looking up their command and control C2 server in a poem posted on GitHub, according to Black Lotus Labs. The malware reading it, dubbed PoeLLM, breaks into exposed AI services and open-source tools, mines cryptocurrency on them and uses them to hunt for new victims. The researchers call the campaign Canto Incognito and believe it is the work of an Italian-speaking threat actor who appears to be in it … More https://www.helpnetsecurity.com/2026/10/08/poellm-malware-github-poem-ai-servers/ The post Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers https://www.helpnetsecurity.com/2026/10/08/poellm-malware-github-poem-ai-servers/ appeared first on Help Net Security https://www.helpnetsecurity.com .