Executive Summary
In 2026, cybersecurity researchers identified the Canto Incognito campaign, deploying PoeLLM malware to build a cryptocurrency mining botnet targeting AI and LLM infrastructure. Active since April 2026, the campaign infected over 3,400 servers, peaking at nearly 2,200 affected systems in mid-June. The Italian-speaking threat actors used a creative technique, hiding command-and-control addresses within poems hosted on GitHub, and targeted enterprise-facing deployments including LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances to exploit their computational power for illicit mining operations.
This incident highlights the growing threat to AI infrastructure as organizations rapidly deploy LLM services without adequate security controls, making them attractive targets for cryptojacking operations due to their powerful computing resources and often inadequate monitoring.
Why This Matters Now
AI infrastructure represents a new high-value target for threat actors seeking computational resources for cryptocurrency mining, with organizations deploying LLM services faster than they can secure them, creating urgent gaps in enterprise security postures.
Attack Path Analysis
The PoeLLM malware campaign targets exposed AI/LLM infrastructure through vulnerability exploitation to establish initial access, then escalates privileges to deploy cryptocurrency miners. Compromised systems are converted into scanning infrastructure for lateral movement across the internet, while maintaining C2 communication through GitHub-hosted poems. The attack focuses on resource theft through cryptojacking operations, leveraging the high-performance compute capabilities of AI infrastructure for financial gain.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploit known vulnerabilities in publicly exposed AI/LLM services including LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances through automated scanning and HTTP POST exploitation
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Acquire Infrastructure: Domains
Application Layer Protocol: Web Protocols
Resource Hijacking
Remote System Discovery
Brute Force
Create or Modify System Process: Systemd Service
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – External Penetration Testing
Control ID: 11.3.1
NYDFS 23 NYCRR 500 – Penetration Testing
Control ID: 500.15
CISA Zero Trust Maturity Model 2.0 – Workload Asset Management
Control ID: WL.AM.2
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
DORA – Identification of ICT Risk
Control ID: Article 8
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.8.8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
AI/LLM infrastructure targeted by PoeLLM cryptojacking malware affecting 3,400+ servers, exploiting compute resources through lateral movement and egress security vulnerabilities.
Computer Software/Engineering
Enterprise LiteLLM, Gotenberg deployments compromised via botnet expansion, requiring zero trust segmentation and multicloud visibility controls for protection.
Financial Services
High-performance computing environments vulnerable to cryptocurrency mining exploitation, demanding encrypted traffic controls and anomaly detection per compliance frameworks.
Health Care / Life Sciences
AI-powered medical infrastructure at risk from Italian-speaking threat actors, necessitating HIPAA-compliant egress filtering and Kubernetes security implementations.
Sources
- PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnethttps://thehackernews.com/2026/10/poellm-malware-infects-3400-servers-to.htmlVerified
- Canto Incognito: Tracking the PoeLLM Malwarehttps://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malwareVerified
- Researchers Find 175,000 Publicly Exposed AI Infrastructurehttps://thehackernews.com/2026/01/researchers-find-175000-publicly.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of the PoeLLM campaign by constraining lateral movement between AI/LLM services and limiting outbound communication paths. The segmentation capabilities could contain cryptomining operations within isolated network zones rather than allowing propagation across the entire infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF visibility capabilities would likely detect anomalous traffic patterns and exploit attempts against AI/LLM services, potentially reducing the success rate of automated vulnerability scanning across the infrastructure.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain the malware's ability to access system-level resources and establish persistent mining operations by limiting privilege scope within isolated workload boundaries.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely prevent compromised AI services from scanning and accessing other internal systems, significantly reducing the campaign's ability to propagate laterally across the infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility capabilities would likely detect unusual GitHub communication patterns from AI infrastructure, potentially identifying the novel C2 channel despite its creative obfuscation technique.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain data exfiltration attempts by monitoring and restricting outbound data flows from AI services to unauthorized external destinations.
Residual cryptocurrency mining operations may continue within segmented boundaries, but resource theft would likely be constrained to individual workload zones rather than spreading across the entire AI infrastructure.
Impact at a Glance
Affected Business Functions
- AI/ML Model Serving and Inference
- Compute Infrastructure Operations
- Document Processing Services
- Enterprise Development Operations
Estimated downtime: 2 days
Estimated loss: N/A
Potential exposure of AI/LLM training data, model parameters, and proprietary algorithms hosted on compromised infrastructure. Risk of unauthorized access to enterprise data processed through infected LiteLLM and Gotenberg services.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between AI/LLM infrastructure and other network segments
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections to cryptocurrency mining pools and suspicious GitHub repositories
- • Enable Multicloud Visibility & Control to detect anomalous scanning behavior and repeated exploitation attempts across AI infrastructure
- • Establish Threat Detection & Anomaly Response capabilities to identify cryptocurrency mining processes and unusual resource consumption patterns
- • Apply Cloud Firewall (ACF) with URL filtering to block access to known mining pools and prevent automated exploitation of vulnerable services



