DKDKCISSPSearch
AI Security

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

DKCISSP News DeskThe Hacker News7 Oct 2026, 9:03 pm
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

The financially motivated campaign, dubbed Canto Incognito , has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service.

Lumen Black Lotus Labs said in a report shared with The Hacker News.

The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a technique that hides the command-and-control (C2) address within a poem the threat actors wrote and hosted in a GitHub repository ( ).

Ryan English, information security engineer at Lumen Technologies, told The Hacker News.

The attacks have been primarily found to single out enterprise, internet-facing deployments such as LiteLLM and Gotenberg, as well as Gitea and Ivanti Sentry appliances.

Evidence indicates that the malware has been active since April 2026, with more than 3400 victim servers identified so far.

Another notable aspect of the campaign is that it repurposes some of the compromised systems to scan the internet for similar instances, send an HTTP POST request to exposed ports on identified targets that instruct them to download the malware from the C2.

The end goal of the campaign is to weaponize known vulnerabilities in publicly exposed services to enlist them into a cryptocurrency mining botnet and convert a subset of them into a scanner to expand the victim pool.

The first commit to the repository was on April 13, 2026.

The targeting of these LLM instances is no coincidence as the intention is to abuse their compute power for illicit cryptocurrency mining.

Lumen Black Lotus Labs has attributed the activity to an Italian-speaking threat actor with moderate confidence based on the presence of Italian-language artifacts and netflow indicators.

What happened

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

The financially motivated campaign, dubbed Canto Incognito , has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service.

Lumen Black Lotus Labs said in a report shared with The Hacker News.

What changed

The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a technique that hides the command-and-control (C2) address within a poem the threat actors wrote and hosted in a GitHub repository ( ).

Ryan English, information security engineer at Lumen Technologies, told The Hacker News.

The attacks have been primarily found to single out enterprise, internet-facing deployments such as LiteLLM and Gotenberg, as well as Gitea and Ivanti Sentry appliances.

Who is affected

Evidence indicates that the malware has been active since April 2026, with more than 3400 victim servers identified so far.

Another notable aspect of the campaign is that it repurposes some of the compromised systems to scan the internet for similar instances, send an HTTP POST request to exposed ports on identified targets that instruct them to download the malware from the C2.

Why it matters

The end goal of the campaign is to weaponize known vulnerabilities in publicly exposed services to enlist them into a cryptocurrency mining botnet and convert a subset of them into a scanner to expand the victim pool.

The first commit to the repository was on April 13, 2026.

Technical details

The targeting of these LLM instances is no coincidence as the intention is to abuse their compute power for illicit cryptocurrency mining.

Lumen Black Lotus Labs has attributed the activity to an Italian-speaking threat actor with moderate confidence based on the presence of Italian-language artifacts and netflow indicators.

Attribution

The Hacker News: Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

MORE IN AI SECURITY

More cybersecurity reporting

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial FirmsThe Hacker News · 8 Oct 2026, 10:17 pmHow AI can fix cybersecurity compliance: From dashboards to continuous execution - Help Net SecurityHelp Net Security · 8 Oct 2026, 10:30 amApple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data AccessThe Hacker News · 7 Oct 2026, 5:11 pmIntellias Agentic ServiceOps applies governed AI across IT operations - Help Net SecurityHelp Net Security · 6 Oct 2026, 6:25 pm