The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In 2026, cybersecurity researchers identified the Canto Incognito campaign, deploying PoeLLM malware to build a cryptocurrency mining botnet targeting AI and LLM infrastructure. Active since April 2026, the campaign infected over 3,400 servers, peaking at nearly 2,200 affected systems in mid-June. The Italian-speaking threat actors used a creative technique, hiding command-and-control addresses within poems hosted on GitHub, and targeted enterprise-facing deployments including LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances to exploit their computational power for illicit mining operations.

This incident highlights the growing threat to AI infrastructure as organizations rapidly deploy LLM services without adequate security controls, making them attractive targets for cryptojacking operations due to their powerful computing resources and often inadequate monitoring.

Why This Matters Now

AI infrastructure represents a new high-value target for threat actors seeking computational resources for cryptocurrency mining, with organizations deploying LLM services faster than they can secure them, creating urgent gaps in enterprise security postures.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The malware used a creative technique of embedding C2 addresses within poems hosted on GitHub repositories, changing words in the poem each time a new C2 server was established.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius of the PoeLLM campaign by constraining lateral movement between AI/LLM services and limiting outbound communication paths. The segmentation capabilities could contain cryptomining operations within isolated network zones rather than allowing propagation across the entire infrastructure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF visibility capabilities would likely detect anomalous traffic patterns and exploit attempts against AI/LLM services, potentially reducing the success rate of automated vulnerability scanning across the infrastructure.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely constrain the malware's ability to access system-level resources and establish persistent mining operations by limiting privilege scope within isolated workload boundaries.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely prevent compromised AI services from scanning and accessing other internal systems, significantly reducing the campaign's ability to propagate laterally across the infrastructure.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility capabilities would likely detect unusual GitHub communication patterns from AI infrastructure, potentially identifying the novel C2 channel despite its creative obfuscation technique.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely constrain data exfiltration attempts by monitoring and restricting outbound data flows from AI services to unauthorized external destinations.

Impact (Mitigations)

Residual cryptocurrency mining operations may continue within segmented boundaries, but resource theft would likely be constrained to individual workload zones rather than spreading across the entire AI infrastructure.

Impact at a Glance

Affected Business Functions

  • AI/ML Model Serving and Inference
  • Compute Infrastructure Operations
  • Document Processing Services
  • Enterprise Development Operations
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of AI/LLM training data, model parameters, and proprietary algorithms hosted on compromised infrastructure. Risk of unauthorized access to enterprise data processed through infected LiteLLM and Gotenberg services.

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between AI/LLM infrastructure and other network segments
  • • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections to cryptocurrency mining pools and suspicious GitHub repositories
  • • Enable Multicloud Visibility & Control to detect anomalous scanning behavior and repeated exploitation attempts across AI infrastructure
  • • Establish Threat Detection & Anomaly Response capabilities to identify cryptocurrency mining processes and unusual resource consumption patterns
  • • Apply Cloud Firewall (ACF) with URL filtering to block access to known mining pools and prevent automated exploitation of vulnerable services

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image