Cryptomining Botnet Hides C2 Addresses in GitHub Poem, Infects 3,400 Servers
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
Threat Actors and Malware Overview
Threat actors have deployed a cryptomining botnet that conceals command and control (C2) server addresses within a poem hosted on GitHub, compromising over 3,400 servers globally. The malware, identified as PoeLLM, targets vulnerable AI services and open-source tools, leveraging them for cryptocurrency mining while expanding its network through automated exploitation. Researchers at Black Lotus Labs attribute the campaign to an Italian-speaking threat group prioritizing financial gain. The operation, named Canto Incognito, has been active since April 2026, with the majority of affected servers located in the United States and Western Europe.
Exploited Vulnerabilities and Targets
The malware primarily exploits outdated versions of open-source AI/LLM platforms such as LiteLLM and Ollama, alongside the PDF conversion tool Gotenberg and the Gitea development toolkit. Attackers target these systems due to their self-hosted nature, internet exposure, and known vulnerabilities that provide access to valuable computational resources.
Discovery and Initial Findings
Discovery of the malware began during investigations into the Ivanti Sentry vulnerability (CVE-2026-10520). In early June 2026, a compromised Ivanti Sentry instance communicated with a server at 5.78.73[.]122, triggering subsequent scans for additional targets. Black Lotus Labs traced the first GitHub commit containing the C2-address-hiding poem to April 13, 2026. Early telemetry suggested the operator was testing the malware’s infection and payload mechanisms.
C2 Infrastructure and Poem-Based Obfuscation
The botnet’s C2 infrastructure is embedded in a GitHub repository under the username “ejejejdfbbebe,” which forks the nodejs.org source code. The poem, titled “On the Nature of Connection,” is stored in a file named dash.css. PoeLLM extracts four specific words from predefined locations in the text and maps them to numerical values using a hard-coded dictionary. These numbers form the IPv4 address of the current C2 server. For example, the words “driver,” “diode,” “decryption,” and “string” corresponded to 92, 119, 165, and 74, creating the address 92.119.165.74. Each update to the poem alters the four keywords, redirecting infected machines to new C2 servers. The repository has undergone 11 revisions since its initial commit, with the malware creator maintaining the same decryption pattern while changing the keyword set.
Botnet Capabilities and Expansion
Once deployed, PoeLLM executes cryptocurrency miners like XMRig and Iron, connecting victims to the Russian Kryptex mining pool. The malware also includes a remote shell, HTTP/S scanning capabilities, and exploit deployment features. Infected servers actively scan for new targets, expanding the botnet’s reach. Recent activity shows the group targeting SSH ports and login interfaces, suggesting experimentation with distributed brute-force attacks, though this functionality remains in early development.
Researcher Response and Recommendations
Black Lotus Labs has blocked traffic to the C2 servers and continues monitoring for new activity. Researchers emphasize the growing risks associated with AI infrastructure, warning that delayed updates to internet-facing tools create opportunities for exploitation. They urge enterprises to integrate AI systems into attack surface management and patching workflows to mitigate threats such as cryptomining, data loss, and lateral movement. The campaign highlights the evolving tactics of threat actors, who increasingly leverage unconventional methods to obfuscate their operations. As AI tools become more prevalent in enterprise environments, securing these systems against malicious use is critical to preventing financial and operational harm.
Black Lotus Labs has blocked traffic to the C2 servers and continues monitoring for new activity.
