Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

The Hacker News by The Hacker News
October 7, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananOct 07, 2026Botnet / Cryptojacking

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service.

“Compromised hosts are reused to expand the botnet,” Lumen Black Lotus Labs said in a report shared with The Hacker News. “Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems.”

The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a “creative” technique that hides the command-and-control (C2) address within a poem the threat actors wrote and hosted in a GitHub repository (“github[.]com/ejejejdfbbebe”). The first commit to the repository was on April 13, 2026.

“Each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words,” Ryan English, information security engineer at Lumen Technologies, told The Hacker News.

The attacks have been primarily found to single out enterprise, internet-facing deployments such as LiteLLM and Gotenberg, as well as Gitea and Ivanti Sentry appliances.

C2 Extraction Logic

The targeting of these LLM instances is no coincidence as the intention is to abuse their compute power for illicit cryptocurrency mining. Evidence indicates that the malware has been active since April 2026, with more than 3400 victim servers identified so far. The infections are concentrated in the U.S. and Western Europe.

“At the peak of operations in mid-June, the campaign involved almost 2,200 affected servers, with nearly 800 active per day,” the cybersecurity company said. “More recent traffic toward SSH and other login portals suggests experimentation with distributed brute-force attacks; that capability’s maturity remains uncertain.”

Another notable aspect of the campaign is that it repurposes some of the compromised systems to scan the internet for similar instances, send an HTTP POST request to exposed ports on identified targets that instruct them to download the malware from the C2.

Lumen Black Lotus Labs has attributed the activity to an Italian-speaking threat actor with moderate confidence based on the presence of Italian-language artifacts and netflow indicators. The end goal of the campaign is to weaponize known vulnerabilities in publicly exposed services to enlist them into a cryptocurrency mining botnet and convert a subset of them into a scanner to expand the victim pool.

“AI infrastructure is becoming an attractive target,” Lumen said. “Exposed AI/LLM services are valuable not only because of software vulnerabilities, but also because they may contain useful data and run on powerful hardware suitable for mining.”



Source link

The Hacker News

The Hacker News

Next Post

The Pentagon Hopes to Speed Up ‘Kill Chain’ AI Buys With 5-Minute Videos

Recommended.

RSAC 2025: AI Is Changing Everything For Security — Except The Hard Problems

RSAC 2025: AI Is Changing Everything For Security — Except The Hard Problems

April 30, 2025
Huawei ICT Competition 2024-2025 Global Final Concludes: AI Empowers Education Transformation and ICT Talent Development

Huawei ICT Competition 2024-2025 Global Final Concludes: AI Empowers Education Transformation and ICT Talent Development

May 24, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio