← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

PoeLLM Malware Infects Over 3,400 Servers, Expanding Crypto Mining Botnet

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • PoeLLM malware targets AI/LLM infrastructure.
  • Over 3,400 servers infected since April 2026.
  • Deploys XMRig and Iron cryptocurrency miners.
  • Compromised servers scan for new targets.

New Malware Targets AI/LLM Infrastructure

Cybersecurity researchers have identified a new malware family, named PoeLLM, which targets exposed artificial intelligence (AI) and large language model (LLM) infrastructure. The financially motivated campaign, dubbed Canto Incognito, aims to deploy cryptocurrency miners and expand its botnet.

Cryptocurrency Mining and Botnet Expansion

The PoeLLM malware installs cryptocurrency miners such as XMRig and Iron, connecting victims to the Russian cryptocurrency mining service Kryptex. Compromised servers are then repurposed to act as scanners and exploit servers, enabling the threat actors to find and infect additional vulnerable systems.

Creative Command-and-Control Mechanism

PoeLLM uses a unique method to hide its command-and-control (C2) address. The C2 address is embedded within a poem hosted on a GitHub repository. The malware extracts the C2 address by interpreting specific words in the poem, which change each time a new C2 is set up.

Widespread Infections and Geographic Focus

The malware has been active since April 2026, infecting over 3,400 servers, primarily in the U.S. and Western Europe. At its peak in mid-June, the campaign involved nearly 2,200 affected servers, with approximately 800 active daily. The attacks specifically target enterprise, internet-facing deployments like LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances, leveraging their compute power for illicit mining.

Attribution and Future Threats

Lumen Black Lotus Labs attributes this activity to an Italian-speaking threat actor. Recent traffic suggests the actor is experimenting with distributed brute-force attacks against SSH and other login portals, indicating potential expansion of their capabilities beyond cryptocurrency mining.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~5 min · 3 stories · Oct 07

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new malware family, PoeLLM, has infected over 3,400 servers since April 2026, targeting AI and LLM infrastructure to deploy cryptocurrency miners. The campaign, dubbed Canto Incognito, reuses compromised hosts to scan for and infect additional vulnerable systems, expanding its botnet.