Full Report
Quoth the LLM, 'More and more'
Analysis Summary
# Incident Report: Campaign "Canto Incognito" (PoeLLM Malware)
## Executive Summary
The "Canto Incognito" campaign, active since April 2026, involves a sophisticated PoeLLM malware targeting enterprise AI infrastructure. The attacker uses "adversarial poetry"—malicious commands hidden within AI-generated poems on GitHub—to dynamically update Command and Control (C2) infrastructure. The primary impact is a large-scale cryptojacking botnet that has compromised over 3,000 servers to mine XMRig and Iron coins.
## Incident Details
- **Discovery Date:** Early June 2026
- **Incident Date:** Active since April 13, 2026
- **Affected Organization:** Multiple (3,000+ servers) including Ivanti Sentry users
- **Sector:** Technology / AI Infrastructure / Enterprise Software
- **Geography:** Primarily United States and Western Europe
## Timeline of Events
### Initial Access
- **Date/Time:** April 13, 2026 (First identified GitHub commit)
- **Vector:** Exploitation of vulnerable, internet-facing AI services and enterprise software.
- **Details:** Attackers targeted LiteLLM, Ollama, Gotenberg (PDF converter), Gitea (software development), and Ivanti Sentry (specifically CVE-2026-10520).
### Lateral Movement
- **Mechanism:** Compromised machines are turned into vulnerability scanners and exploit servers to identify and infect additional vulnerable devices on the network or internet.
### Data Exfiltration/Impact
- **Cryptojacking:** Deployment of XMRig and Iron miners to Kryptex mining infrastructure.
- **Resource Hijacking:** Unauthorized use of high-performance GPU hardware intended for AI workloads.
- **Botnet Recruitment:** Conspection of victims into a persistent botnet for further scanning and exploitation.
### Detection & Response
- **Discovery:** Black Lotus Labs (Lumen) identified the malware while investigating an Ivanti Sentry compromise where a victim contacted a known malicious C2.
- **Response Actions:** Public disclosure of the "Canto Incognito" campaign and C2 IP mapping to enable defender blocking.
## Attack Methodology
- **Initial Access:** Exploitation of known vulnerabilities (e.g., CVE-2026-10520) in AI and web services.
- **Persistence:** Botnet conscription; malware remains active, periodically checking a GitHub repository for updates.
- **Defense Evasion:** Use of "Adversarial Poetry" to hide C2 IP addresses within a legitimate-looking CSS file (`dash.css`) on GitHub, evading automated security flags and human inspection.
- **Discovery:** Scanning for vulnerable open-source AI tools (LiteLLM, Ollama).
- **Lateral Movement:** Automated scanning and exploit deployment from compromised nodes.
- **Exfiltration:** N/A (Focus is on resource theft/mining).
- **Impact:** Financial gain through cryptojacking and operational disruption via resource exhaustion.
## Impact Assessment
- **Financial:** High (significant GPU resource consumption and electricity costs for victims).
- **Data Breach:** None reported, though the level of access suggests potential for data theft.
- **Operational:** Significant disruption to AI development and production environments due to hijacked compute power.
- **Reputational:** Public exposure of vulnerable AI infrastructure.
## Indicators of Compromise
- **Network Indicators:**
- 5.78.73[.]122 (C2 Server)
- Communications with Kryptex mining pools.
- **File Indicators:**
- `dash.css` located in a GitHub fork of nodejs.org.
- Presence of XMRig or Iron miner binaries.
- **Behavioral Indicators:**
- AI servers initiating outbound scans for LiteLLM or Ollama vulnerabilities.
- Unexpectedly high GPU utilization.
- Automated parsing of GitHub-hosted text files for IP extraction.
## Response Actions
- **Containment:** Blocked known C2 IP addresses at the network level.
- **Eradication:** Removal of PoeLLM malware and associated mining binaries (XMRig/Iron).
- **Recovery:** Patching Ivanti Sentry (CVE-2026-10520) and securing open-source AI services (LiteLLM/Ollama).
## Lessons Learned
- **AI Infrastructure as a Target:** High-performance AI servers (GPUs) are high-value targets for cryptojacking due to their processing power.
- **Novel Obfuscation:** Traditional security tools fail to flag malicious intent when it is hidden in natural language (poetry) without code-like structures or links.
- **Supply Chain/Third-Party Vulnerabilities:** Open-source AI wrappers and PDF tools are often less scrutinized than core infrastructure, providing an easy entry point.
## Recommendations
- **Patch Management:** Immediately patch Ivanti Sentry and ensure all AI-related services (Ollama, LiteLLM) are not exposed to the public internet without authentication.
- **Egress Filtering:** Implement strict egress filtering to prevent internal servers from communicating with unauthorized mining pools or GitHub repositories not required for production.
- **Monitoring:** Monitor GPU usage for anomalies that could indicate unauthorized mining activities.
- **AI Security:** Implement specialized security reviews for AI infrastructure, recognizing that AI-enabled tools may introduce unpatched vulnerabilities.