Lumen's Black Lotus Labs has published research on a malware family it names PoeLLM, in a campaign it tracks as Canto Incognito. The victim count is large and the payload is a cryptocurrency miner, which on its own would make this an ordinary story.

What makes it worth reading is the step in the middle: how an infected machine finds out where to report.

The address is in a poem

The malware does not carry a command-and-control address. It carries instructions for reading one.

Those instructions point at a poem titled On the Nature of Connection, hosted in a GitHub repository. The binary fetches it and pulls four pieces of text from fixed positions — what follows "In the silent hum of", what sits between "each pulse of" and "threading", what follows "Beyond the wall of", and the word before "of distant servers".

Each of those four words is then looked up in a dictionary compiled into the malware, which maps words to numbers. Lumen gives two entries as examples: "driver" is 92, "diode" is 119. The four resulting numbers, in order, are the four octets of an IPv4 address.

To move the botnet, the operator edits the poem. Black Lotus Labs counts eleven rewrites since the first commit on 13 April, each one sending every infected machine somewhere new.

Why this is more than a flourish

Strip away the poetry and what is left is a resolution step that produces nothing worth alerting on.

An infected host fetching a text file from GitHub over HTTPS looks like any build server, any package manager, any developer laptop. There is no domain to seize, because there is no domain. There is no DNS record to sinkhole. The address never crosses the network as an address — it crosses as four English words in a poem, and is assembled on the victim.

It is also cheap to rotate. Changing a hardcoded C2 means shipping a new binary to every infected machine. Changing this one means a commit.

This is now a familiar shape rather than a novelty. The npm registry carried the MALFEX operator's payloads for three years, because a package registry is not a thing an organisation blocks. Neither is a code host. The list of services that every network must allow out to is short, well known, and being worked through.

What it breaks into

PoeLLM goes after exposed services rather than people, and the target list is specific: LiteLLM and Ollama, Gotenberg, Gitea, and Ivanti Sentry appliances. Scanning concentrates on port 4000 for LiteLLM and port 3000 for Gotenberg.

The named entry point is CVE-2026-42271, a command injection in LiteLLM reached through its connection-test endpoint. Lumen also lists two 2018 flaws in the Boa web server used by some routers, which suggests the operator is not fussy about the age of what it exploits.

A successful request tells the target to fetch its payload from the C2 on port 81. The payload is an ELF binary that installs itself as libgcrypt, borrowing the name of a real cryptographic library.

Mining is only half of it

The payload runs XMRig and a second miner called Iron, pointed at Kryptex, a Russian mining service. That is the revenue.

The other job is growth. Infected servers are turned into scanners and exploit servers: they go looking for the next victim and hand it back. The botnet recruits using the machines it already holds, which is how a campaign aimed at a handful of niche products reached the numbers it did.

Lumen notes that the most recent activity has moved on to SSH ports and other login portals, and reads it as the operator experimenting with distributed brute forcing. That would be a different business from mining.

The two numbers do not agree

Black Lotus Labs gives two victim counts, and they are not the same.

One sentence says that since it emerged in April, PoeLLM has impacted almost 2,200 victim servers. Another says more than 3,400 victim servers, with peak activity exceeding 800 active per day. A third describes the mid-June peak as almost 2,200 affected servers with nearly 800 active daily.

The natural reconciliation is that one figure counts a moment and the other counts cumulatively, but the research does not say which is which. Both appear in the same post. We are carrying both rather than reporting the larger one as the finding.

Attribution, at the confidence it was given

Lumen assesses that PoeLLM is associated with an Italian-speaking threat actor, on the basis of Italian-language artefacts, netflow data and the services hosted on one particular server.

The stated confidence attaches to something narrower than the headline implies: Lumen says it assesses with moderate confidence that the server in question is the operator's administrative interface. Moderate confidence on the infrastructure, language artefacts on the actor. That is a reasonable thing to publish and a thin thing to build on.

Black Lotus Labs says it has null-routed traffic to and from the C2 servers across its backbone, and has published indicators.

What to do

  • If LiteLLM, Ollama, Gotenberg or Gitea is reachable from the internet, that is the exposure. Ports 3000 and 4000 are being swept for it specifically.
  • Patch LiteLLM for CVE-2026-42271, and check whether the connection-test endpoint answers without authentication.
  • Log outbound fetches from servers to raw file hosts. This campaign resolves its C2 through one, and it will not be the last to do so.
  • Look for a process called libgcrypt that is not the library.

What is not established

  • Which victim figure is correct, and what each of the two counts.
  • How much was mined, and what it was worth.
  • Whether the repository hosting the poem is still live, and whether GitHub was notified or acted.
  • Which flaws were used against Gitea and Ollama. Only the LiteLLM and Ivanti Sentry identifiers are named.
  • Whether the Italian-language artefacts point to the operator or to code borrowed from someone else.