Full Report
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including
Analysis Summary
# Tool/Technique: PoeLLM Malware (Canto Incognito Campaign)
## Overview
PoeLLM is a newly identified malware family discovered in 2026 that targets exposed Artificial Intelligence (AI) and Large Language Model (LLM) infrastructure. Its primary objective is to hijack the high-performance compute power typical of AI servers to mine cryptocurrency. The malware is a core component of the "Canto Incognito" campaign, which functions as a self-expanding botnet.
## Technical Details
- **Type:** Malware Family / Botnet Agent
- **Platform:** Linux / Unix (implied by targeting of LiteLLM, Gotenberg, Gitea, and Ivanti Sentry)
- **Capabilities:** Steganographic C2 extraction, Vulnerability Exploitation, Internet Scanning, Cryptojacking, Brute-forcing.
- **First Seen:** April 13, 2026 (Initial GitHub commit for C2 hosting).
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1190 - Exploit Public-Facing Application]
- **[TA0011 - Command and Control]**
- [T1102.001 - Web Service: Dead Drop Resolver] (GitHub-hosted poem)
- [T1001 - Data Staging / Steganography] (Hiding C2 in word keys)
- **[TA0007 - Discovery]**
- [T1046 - Network Service Scanning]
- **[TA0040 - Impact]**
- [T1496 - Resource Hijacking] (Cryptomining)
- **[TA0008 - Lateral Movement]**
- [T1110 - Brute Force] (Observed experimenting with SSH/login portals)
## Functionality
### Core Capabilities
- **C2 Dead Drop Resolution:** The malware connects to a specific GitHub repository (`github[.]com/ejejejdfbbebe`) and reads a poem. The actual C2 IP address is derived from a key or algorithm associated with specific words in the poem, allowing the actor to change C2s simply by editing the text.
- **Cryptojacking:** Deploys known miners such as **XMRig** and **Iron**, connecting them to the Russian-based **Kryptex** mining service.
- **Botnet Expansion:** Compromised hosts are converted into scanners. They autonomously scan the internet for other vulnerable services (LiteLLM, Gotenberg, Gitea, etc.).
### Advanced Features
- **Worm-like Propagation:** Once a scanner node identifies a target, it sends an HTTP POST request to the vulnerable host, instructing it to download and execute the PoeLLM payload.
- **AI Infrastructure Targeting:** Specifically looks for infrastructure with powerful GPUs or high-thread CPUs to maximize mining yields.
## Indicators of Compromise
- **File Names:** XMRig, Iron (standard miner binaries).
- **Network Indicators:**
- `github[.]com/ejejejdfbbebe` (C2 Resolution Source)
- Connections to Kryptex mining pools (e.g., `kryptex[.]network`).
- **Behavioral Indicators:**
- High CPU/GPU utilization on AI/LLM servers.
- Outbound HTTP POST requests to random internet IPs on ports associated with LiteLLM, Gitea, or Ivanti.
- Unexpected SSH outbound traffic (brute-force activity).
## Associated Threat Actors
- **Canto Incognito:** Attributed with moderate confidence to an Italian-speaking threat actor/group due to Italian-language artifacts in the code and netflow data.
## Detection Methods
- **Behavioral Detection:** Monitor for unexpected outbound connections from LLM/AI servers, particularly to GitHub or known mining pools. Monitor for unusual "Scanning" behavior (rapid outbound connection attempts to public IPs).
- **Signature-based:** Detect known XMRig and Iron miner binaries.
- **Network Inspection:** Look for the specific URI pattern used in the GitHub repository mentioned above.
## Mitigation Strategies
- **Vulnerability Management:** Patch internet-facing instances of Gitea, Ivanti Sentry, LiteLLM, and Gotenberg immediately.
- **Network Segmentation:** AI/LLM infrastructure should not have unrestricted outbound internet access. Use a proxy or firewall to whitelist only necessary domains.
- **Access Control:** Disable or restrict public access to management ports and LLM API endpoints. Implement strong authentication for SSH and login portals.
## Related Tools/Techniques
- **XMRig:** Open-source Monero miner frequently bundled with malware.
- **Dead Drop Resolvers:** Similar to techniques used by APTs where social media or code repositories host encoded C2 instructions.