Lumen Black Lotus Labs detailed PoeLLM, the malware behind the financially motivated Canto Incognito campaign, which has infected more than 3,400 internet-facing servers since April 2026. The actor hides its command-and-control address inside a poem stored in a GitHub repository, changing a few words whenever it rotates infrastructure. It exploits known vulnerabilities in exposed services such as LiteLLM, Gotenberg, Gitea, and Ivanti Sentry, then installs XMRig and Iron miners to abuse victim compute for cryptocurrency mining through a Russian mining service. Compromised hosts become scanners and exploit servers that spread the malware further, and recent traffic suggests experimentation with distributed brute-force attacks.