NewsLayer.com

Crypto

breaking

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and…

The Hacker News

Publisher

Oct 7, 2026 at 3:33 PM UTC · 2 phút đọc

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Image via The Hacker News
Đang dịch…

Ravie LakshmananOct 07, 2026Botnet / Cryptojacking

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service.

"Compromised hosts are reused to expand the botnet," Lumen Black Lotus Labs said in a report shared with The Hacker News. "Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems."

The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a "creative" technique that hides the command-and-control (C2) address within a poem the threat actors wrote and hosted in a GitHub repository ("github[.]com/ejejejdfbbebe"). The first commit to the repository was on April 13, 2026.

"Each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words," Ryan English, information security engineer at Lumen Technologies, told The Hacker News.