Threat
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
First reported thehackernews.com
Page published
Earliest dated coverage: 7 Oct 2026 · First observed: 7 Oct 2026 · Latest dated coverage: 7 Oct 2026
Coverage timeline
Single-source incident — one report is available.
Why it matters
PoeLLM demonstrates that attackers are now actively scanning for and compromising exposed AI/LLM infrastructure to build self-propagating cryptomining botnets, making unsecured model-serving hosts a direct target for financially motivated actors.
Lumen Black Lotus Labs reported a financially motivated campaign dubbed Canto Incognito that uses malware codenamed PoeLLM to target exposed AI and large language model (LLM) infrastructure, having infected more than 3,400 servers to deploy cryptocurrency miners (XMRig and Iron) tied to the Russian mining service Kryptex. Compromised hosts are repurposed as scanners and exploit servers to find and infect additional vulnerable systems, expanding the botnet.