As reported by The Hacker News, Lumen Black Lotus Labs has uncovered a financially motivated campaign — dubbed Canto Incognito — that has compromised over 3,400 servers since April 2026 by targeting exposed AI and LLM infrastructure. The associated malware, named PoeLLM, deploys cryptocurrency miners (XMRig and Iron), routes victims through the Russian mining service Kryptex, and repurposes infected hosts into self-propagating scan-and-exploit nodes.
Why This Campaign Demands Attention
Shield53 assesses this campaign as significant for three converging reasons:
Who Is Most Exposed
Organizations running internet-facing instances of LiteLLM, Gotenberg, Gitea, or Ivanti Sentry are the primary target set. Deployments in the U.S. and Western Europe account for the majority of observed infections, with peak activity in mid-June 2026 reaching approximately 2,200 affected servers (~800 active daily). Any organization that has stood up LLM orchestration infrastructure without hardening network exposure should consider themselves in the target zone.
The campaign also shows experimentation with distributed brute-force attacks against SSH and other login portals — an early indicator that the actor is expanding beyond vulnerability exploitation into credential-based access.
Broader Implications for AI Security Teams
This campaign underscores a reality that Shield53 has been tracking: as organizations rush to deploy AI infrastructure, many are exposing management consoles, inference endpoints, and orchestration layers (like LiteLLM) directly to the internet with default credentials or unpatched CVEs. AI infrastructure is now a first-class attack surface, and adversaries are actively profiling it. The compute density that makes these systems valuable for legitimate workloads also makes them premium targets for cryptojacking operators.
Attribution to an Italian-speaking threat actor with moderate confidence suggests this is a criminal operation with regional roots but global targeting — consistent with the financially motivated cryptojacking ecosystem rather than nation-state activity.
Shield53 Recommendations — What You Should Do
Immediate Actions
- Inventory exposed AI services: Identify any internet-facing instances of LiteLLM, Gotenberg, Gitea, or Ivanti Sentry. Move management interfaces behind VPN or zero-trust network access (ZTNA). No LLM orchestration console should be directly reachable from the public internet.
- Patch all referenced products to the latest vendor releases. If you cannot patch immediately, apply vendor-recommended mitigations or take the service offline.
- Block GitHub-based C2 indicators: Review egress traffic for connections to the referenced GitHub repository and associated derived C2 endpoints. Implement alerts for anomalous outbound connections from AI infrastructure hosts.
- Hunt for XMRig and Iron miners: Deploy detection rules for known cryptocurrency miner process names, outbound connections to mining pools, and Kryptex-related network indicators.
- Monitor for propagation behavior: Look for servers initiating high-volume scanning or HTTP POST activity to external IPs — a hallmark of infected nodes acting as scan/exploit servers.
- Lock down SSH: Given the observed brute-force experimentation, enforce key-based authentication, rate limiting, and fail2ban or equivalent. Disable password authentication entirely on any host reachable from the internet.
Strategic Hardening
- Implement network segmentation isolating AI/ML compute pools from general corporate infrastructure.
- Deploy runtime threat detection on GPU-enabled hosts — cryptojackers can be caught by monitoring for unexpected GPU utilization spikes.
- Establish a process for rapid patching of AI infrastructure components, which often lag behind traditional enterprise patching SLAs.