Lumen's Canto Incognito report tracks PoeLLM malware that uses LLMs for command and control, demonstrating LLM-powered malware as an emerging threat vector.
state: seedheat: mediumuncertainty: mediumconvergesscott: highagentic-security llm-malware threat-intelligenceLumen
What is this?
Lumen's Black Lotus Labs published the 'Canto Incognito' report (April 13, 2026) tracking PoeLLM malware that has compromised 3,400+ exposed AI/LLM servers since April 2026. The malware targets vulnerable open-source AI services (LiteLLM, Ollama) and uses a novel poetry-derived C2 mechanism โ translating words from a GitHub-hosted poem into C2 server addresses via a custom conversion key. Italian-speaking threat actors operate the campaign for cryptocurrency mining and botnet expansion, turning infected hosts into scanners for further victims. The snippets are consistent across multiple security outlets; no conflicting accounts appear in the supplied results.
Why it matters to Scott
Lumen's Black Lotus Labs has independently documented the first major in-the-wild instance of the exact threat class Scott's agent-security frameworks anticipate: LLM-powered malware (PoeLLM) compromising 3,400+ exposed AI inference services (LiteLLM, Ollama) and repurposing them as C2 infrastructure with novel poetry-derived obfuscation. This converges with his agent-addressability framework's warning about exposed delegation surfaces, breach-doesnt-compose's 'assume every wall falls' posture, padded-cell-agent-architecture and deterministic-agent-control-plane as prescribed containment, agent-provenance-stack's authorisation chain that the malware entirely bypasses, and architecture-not-vibes/ai-readiness-staircase's insistence that runtime containment must precede governance. The targeting of LiteLLM and Ollama โ which Scott himself operates as his primary model gateway (dev:technology.litellm, dev:technology.ollama, dev:project.gamepc) โ makes this a direct bearing on his infrastructure and a dated-receipts opportunity for his consulting practice (work:project.leverageai).
ip:framework.agent-addressabilityip:framework.breach-doesnt-composeip:framework.padded-cell-agent-architectureip:framework.agent-provenance-stackip:framework.architecture-not-vibesip:framework.ai-readiness-staircaseip:framework.12-factor-agents-frameworkip:framework.five-surface-loop-anatomyip:framework.generative-pendulumdev:technology.litellmdev:technology.ollamadev:project.gamepcdev:project.silo-osdev:concept.deterministic-agent-control-planedev:concept.guarded-agent-inboxdev:concept.cheap-model-front-doorwork:project.leverageairadar:alibi-malware-analysis-cover-storiesradar:abliterated-weights-agent-backdoorradar:aegis-inline-ebpf-agent-containmentradar:agent-security-framework-portabilityradar:agent-screenshot-data-leaksradar:agentshield-offline-agent-scannerradar:agentsec-static-config-auditingradar:abyss-acp-agent-isolationradar:actualis-local-coding-agent-observabilityradar:acs-local-skill-risk-catalog
queries asked of Scott's wikis
- agentic-security threat models for LLM-powered malware and C2 obfuscation
- open-source AI/LLM service exposure risks (LiteLLM, Ollama, local inference endpoints)
- supply chain and infrastructure targeting of AI developer tooling
- LLM/agent security frameworks and defensive patterns Scott has written or built
- model sovereignty and local inference economics as they relate to attack surface
- cryptojacking botnet evolution targeting GPU/accelerator workloads
Measured heat
now 0 pts/hpeak 0 pts/hcomments 0/hpeers p16momentum: steady1 platformsage 47h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion
How the heat travelled
pace: p13 vs 968 stories at the 24h mark (now 47h old) โ behind addom-local-coding-harness (0.5x)
Evidence (1) โ โญ canonical anchor
Interpretation history
2026-10-09T22:14:51Z
grounded: converges/high โ Lumen's Black Lotus Labs has independently documented the first major in-the-wild instance of the exact threat class Scott's agent-security frameworks anticipat
2026-10-09T21:59:17Z
case created โ Concrete security incident tracking LLM-powered malware; agentic-security is a hot topic with 132 open episodes.
Decision trace
- 10-10 12:05attention_communicatedLumen's Black Lotus Labs reports the first major in-the-wild LLM-powered malware (PoeLLM) compromising over 3,400 exposed AI inference services โ including LiteLLM and Ollama instances โ and repu
- 10-10 12:05attention_routeActive threat to infrastructure Scott runs today; waiting for the next briefing (6 hours) delays potential mitigation. This is a concrete, observed attack pattern, not a theoretical risk.
- 10-10 11:23attention_routeActive threat to infrastructure Scott runs today; waiting for the next briefing (6.5 hours) delays potential mitigation. This is a concrete, observed attack pattern, not a theoretical risk.
- 10-10 11:18attention_candidatecreate
- 10-10 09:14groundLumen's Black Lotus Labs has independently documented the first major in-the-wild instance of the exact threat class Scott's agent-security frameworks anticipate: LLM-powered malware (PoeLLM
- 10-10 08:59createConcrete security incident tracking LLM-powered malware; agentic-security is a hot topic with 132 open episodes.