Cybersecurity researchers have identified a new malware family, named PoeLLM, which targets exposed artificial intelligence (AI) and large language model (LLM) infrastructure. The financially motivated campaign, dubbed Canto Incognito, aims to deploy cryptocurrency miners and expand its botnet.
The PoeLLM malware installs cryptocurrency miners such as XMRig and Iron, connecting victims to the Russian cryptocurrency mining service Kryptex. Compromised servers are then repurposed to act as scanners and exploit servers, enabling the threat actors to find and infect additional vulnerable systems.
PoeLLM uses a unique method to hide its command-and-control (C2) address. The C2 address is embedded within a poem hosted on a GitHub repository. The malware extracts the C2 address by interpreting specific words in the poem, which change each time a new C2 is set up.
The malware has been active since April 2026, infecting over 3,400 servers, primarily in the U.S. and Western Europe. At its peak in mid-June, the campaign involved nearly 2,200 affected servers, with approximately 800 active daily. The attacks specifically target enterprise, internet-facing deployments like LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances, leveraging their compute power for illicit mining.
Lumen Black Lotus Labs attributes this activity to an Italian-speaking threat actor. Recent traffic suggests the actor is experimenting with distributed brute-force attacks against SSH and other login portals, indicating potential expansion of their capabilities beyond cryptocurrency mining.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new malware family, PoeLLM, has infected over 3,400 servers since April 2026, targeting AI and LLM infrastructure to deploy cryptocurrency miners. The campaign, dubbed Canto Incognito, reuses compromised hosts to scan for and infect additional vulnerable systems, expanding its botnet.