Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
What happened
Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The malware (software written to damage a system or steal from it) reading it, dubbed PoeLLM, breaks into exposed AI services and open-source tools, mines cryptocurrency on them and operates with them to hunt for new victims. The researchers call the campaign Canto Incognito and believe it is the work of an Italian-speaking threat actor (the person or group behind an attack) who appears to be in it โฆ More โ The post Cryptomining botnet (a network of hijacked machines controlled by one operator) hides C2 addresses in GitHub poem, infects over 3,400 servers appeared first on Help Net Security .
Sources & evidence
- Help Net Security Reporting source
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers โ
https://www.helpnetsecurity.com/2026/10/08/poellm-malware-github-poem-ai-servers/