PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service.

"Compromised hosts are reused to expand the botnet," Lumen Black Lotus Labs said in a report shared with The Hacker News. "Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems."

The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a "creative" technique that hides the command-and-control (C2) address within a poem the threat actors wrote and hosted in a GitHub repository ("github[.]com/ejejejdfbbebe"). The first commit to the repository was on April 13, 2026.

"Each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words," Ryan English, information security engineer at Lumen Technologies, told The Hacker News.

The attacks have been primarily found to single out enterprise, internet-facing deployments such as LiteLLM and Gotenberg, as well as Gitea and Ivanti Sentry appliances.

C2 Extraction Logic

The targeting of these LLM instances is no coincidence as the intention is to abuse their compute power for illicit cryptocurrency mining. Evidence indicates that the malware has been active since April 2026, with more than 3400 victim servers identified so far. The infections are concentrated in the U.S. and Western Europe.

"At the peak of operations in mid-June, the campaign involved almost 2,200 affected servers, with nearly 800 active per day," the cybersecurity company said. "More recent traffic toward SSH and other login portals suggests experimentation with distributed brute-force attacks; that capability’s maturity remains uncertain."

Another notable aspect of the campaign is that it repurposes some of the compromised systems to scan the internet for similar instances, send an HTTP POST request to exposed ports on identified targets that instruct them to download the malware from the C2.

Lumen Black Lotus Labs has attributed the activity to an Italian-speaking threat actor with moderate confidence based on the presence of Italian-language artifacts and netflow indicators. The end goal of the campaign is to weaponize known vulnerabilities in publicly exposed services to enlist them into a cryptocurrency mining botnet and convert a subset of them into a scanner to expand the victim pool.

"AI infrastructure is becoming an attractive target," Lumen said. "Exposed AI/LLM services are valuable not only because of software vulnerabilities, but also because they may contain useful data and run on powerful hardware suitable for mining."

进一步分析

免费工具,针对本文主题进一步深挖分析:

source: TheHackerNews