Ravie LakshmananOct 07, 2026Botnet / Cryptojacking
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and…
The Hacker News
Publisher
Oct 7, 2026 at 3:33 PM UTC · 2 min de lectura
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.
The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service.
"Compromised hosts are reused to expand the botnet," Lumen Black Lotus Labs said in a report shared with The Hacker News. "Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems."
The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a "creative" technique that hides the command-and-control (C2) address within a poem the threat actors wrote and hosted in a GitHub repository ("github[.]com/ejejejdfbbebe"). The first commit to the repository was on April 13, 2026.
"Each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words," Ryan English, information security engineer at Lumen Technologies, told The Hacker News.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
