AnalysisCybersecurityOctober 7, 2026

PoeLLM malware infects 3,400+ servers to mine crypto

Read original source →thehackernews.com

Lumen Black Lotus Labs tied the "Canto Incognito" campaign to PoeLLM, which hides its C2 address inside a poem hosted in a GitHub repo, changing a few words per new C2. Targets include LiteLLM, Gotenberg, Gitea and Ivanti Sentry; peak hit ~2,200 servers in mid-June.

1 source

More stories today

Open the live feed