As the PoeLLM malware expands its reach, it is increasingly focusing on lateral movement through aggressive brute-force attacks on organizational SSH configurations. This shift represents a significant escalation in the Canto Incognito campaign, which has been identified as a highly targeted operation against the modern technological backbone. Since its emergence in April 2026, the campaign has successfully infiltrated more than 3,400 servers, primarily concentrated across the United States and Western Europe. Researchers at Black Lotus Labs have pointed to an Italian-speaking threat actor who demonstrates a profound understanding of how software development and artificial intelligence environments are interconnected. The primary objective appears to be financial gain, but the methods utilized to achieve this end are far from ordinary. By focusing on high-performance infrastructure, the attackers ensure they have the maximum possible compute power for their activities, creating a ripple effect of disruption.
Sophisticated Mechanics: The Canto Incognito Campaign
Dead Drop Resolvers: Utilizing GitHub for Stealth
The attackers behind PoeLLM have introduced a novel method for maintaining communication with infected nodes by utilizing what researchers describe as dead drop resolvers. Instead of relying on hard-coded internet protocol addresses that security software can easily detect and block, the malware seeks its instructions from a publicly accessible GitHub repository. Specifically, it scans for a seemingly innocuous Cascading Style Sheets file that contains a poem titled On the Nature of Connection. This approach allows the threat actor to hide malicious command-and-control data in plain sight, blending in with legitimate developer traffic that frequently reaches out to GitHub for library updates and configuration files. By leveraging a reputable platform, the malware effectively bypasses many traditional perimeter defenses that are conditioned to trust traffic coming from major code hosting services. This level of obfuscation ensures that the botnet remains operational even when individual nodes are identified and removed.
Poetic Obfuscation: Dynamic Address Resolution
The true ingenuity of this mechanism lies in how the IPv4 addresses are deciphered from the poetic text. PoeLLM utilizes a complex system where specific words located at predetermined positions within the poem are matched against a hard-coded internal dictionary. This process allows the malware to dynamically reconstruct the current address of the control server without ever having that address stored in a readable format within its own code. Throughout the observation period starting in April 2026, researchers witnessed eleven distinct updates to the poem on GitHub, each of which successfully redirected the entire botnet to a fresh server. This seamless rotation makes it incredibly difficult for law enforcement or security teams to dismantle the infrastructure, as the head of the operation can be moved in minutes. The use of an Italian-speaking persona in the underlying code suggests a specific cultural origin for the developer, adding another layer of complexity to the ongoing forensic attribution effort.
Enterprise Vulnerabilities: Targets and Defensive Measures
Exploiting Modern Tools: The AI Application Surface
The targeting strategy of the Canto Incognito campaign highlights a growing gap in how organizations manage their internal AI and Large Language Model deployments. The malware specifically looks for vulnerabilities in self-hosted tools like LiteLLM and Ollama, which have seen a massive surge in corporate adoption throughout 2026. Many of these infections occur because administrators fail to update their local AI instances, leaving known flaws open for exploitation. For instance, the command injection vulnerability in LiteLLM, tracked as CVE-2026-42271, has been a primary entry point for the PoeLLM payload. Other targets include PDF conversion utilities like Gotenberg and version control systems like Gitea, which are often found in the same development environments as AI models. These tools are frequently deployed in containers with excessive permissions, allowing the malware to quickly gain a foothold and begin its reconnaissance of the surrounding internal network and high-value data assets.
Operational Impact: Mitigation and Past Responses
The rapid rise of the Canto Incognito campaign demonstrated that the speed of AI integration often left security teams struggling to maintain adequate defenses. It became clear that internet-exposed services like Ivanti Sentry, plagued by vulnerabilities such as CVE-2026-10520, required immediate attention within standard patch management cycles. Organizations that successfully mitigated these risks did so by implementing strict egress filtering to prevent unauthorized connections to external repositories like GitHub for configuration data. Furthermore, increasing the scrutiny of logs for unusual SSH login attempts helped identify early stages of lateral movement before significant damage occurred. Security professionals emphasized that treating AI infrastructure with the same rigor as traditional web servers was the only way to prevent resource abuse. Ultimately, the industry moved toward a zero-trust model for all self-hosted LLM components, ensuring that even if one service fell, the rest of the network remained secure.
