2026-10-11 16:38 UTC

Lumen's Canto Incognito report tracks PoeLLM malware that uses LLMs for command and control, demonstrating LLM-powered malware as an emerging threat vector.

state: seedheat: mediumuncertainty: mediumconvergesscott: highagentic-security llm-malware threat-intelligenceLumen

What is this?

Lumen's Black Lotus Labs published the 'Canto Incognito' report (April 13, 2026) tracking PoeLLM malware that has compromised 3,400+ exposed AI/LLM servers since April 2026. The malware targets vulnerable open-source AI services (LiteLLM, Ollama) and uses a novel poetry-derived C2 mechanism โ€” translating words from a GitHub-hosted poem into C2 server addresses via a custom conversion key. Italian-speaking threat actors operate the campaign for cryptocurrency mining and botnet expansion, turning infected hosts into scanners for further victims. The snippets are consistent across multiple security outlets; no conflicting accounts appear in the supplied results.

Why it matters to Scott

Lumen's Black Lotus Labs has independently documented the first major in-the-wild instance of the exact threat class Scott's agent-security frameworks anticipate: LLM-powered malware (PoeLLM) compromising 3,400+ exposed AI inference services (LiteLLM, Ollama) and repurposing them as C2 infrastructure with novel poetry-derived obfuscation. This converges with his agent-addressability framework's warning about exposed delegation surfaces, breach-doesnt-compose's 'assume every wall falls' posture, padded-cell-agent-architecture and deterministic-agent-control-plane as prescribed containment, agent-provenance-stack's authorisation chain that the malware entirely bypasses, and architecture-not-vibes/ai-readiness-staircase's insistence that runtime containment must precede governance. The targeting of LiteLLM and Ollama โ€” which Scott himself operates as his primary model gateway (dev:technology.litellm, dev:technology.ollama, dev:project.gamepc) โ€” makes this a direct bearing on his infrastructure and a dated-receipts opportunity for his consulting practice (work:project.leverageai).
ip:framework.agent-addressabilityip:framework.breach-doesnt-composeip:framework.padded-cell-agent-architectureip:framework.agent-provenance-stackip:framework.architecture-not-vibesip:framework.ai-readiness-staircaseip:framework.12-factor-agents-frameworkip:framework.five-surface-loop-anatomyip:framework.generative-pendulumdev:technology.litellmdev:technology.ollamadev:project.gamepcdev:project.silo-osdev:concept.deterministic-agent-control-planedev:concept.guarded-agent-inboxdev:concept.cheap-model-front-doorwork:project.leverageairadar:alibi-malware-analysis-cover-storiesradar:abliterated-weights-agent-backdoorradar:aegis-inline-ebpf-agent-containmentradar:agent-security-framework-portabilityradar:agent-screenshot-data-leaksradar:agentshield-offline-agent-scannerradar:agentsec-static-config-auditingradar:abyss-acp-agent-isolationradar:actualis-local-coding-agent-observabilityradar:acs-local-skill-risk-catalog
queries asked of Scott's wikis
  • agentic-security threat models for LLM-powered malware and C2 obfuscation
  • open-source AI/LLM service exposure risks (LiteLLM, Ollama, local inference endpoints)
  • supply chain and infrastructure targeting of AI developer tooling
  • LLM/agent security frameworks and defensive patterns Scott has written or built
  • model sovereignty and local inference economics as they relate to attack surface
  • cryptojacking botnet evolution targeting GPU/accelerator workloads

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p16momentum: steady1 platformsage 47h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion

How the heat travelled

10-09 17:27โญ origin directly observedCanto incognito: tracking the PoeLLM malware
simonpure on hacker news
โ€”
10-09 17:27amplified on hacker news ๐Ÿ‘‘hn.story.50023858
simonpure
peak 1 ยท 0 comments ยท 106% of case engagement
10-09 19:34our radar first saw it ยท +2.1hdiscovery anchor: hn.story.50023858โ€”
pace: p13 vs 968 stories at the 24h mark (now 47h old) โ€” behind addom-local-coding-harness (0.5x)

Evidence (1) โ€” โญ canonical anchor

sourceobjectauthorscorecomments
๐ŸŸง hn โญCanto incognito: tracking the PoeLLM malwaresimonpure10

Interpretation history

Decision trace