MediumNewsLLM-specific
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
- Published
- Record updated
Summary
Lumen Black Lotus Labs reported a financially motivated campaign, dubbed Canto Incognito, that deploys a malware family it calls PoeLLM against exposed AI and LLM infrastructure. The malware installs XMRig and Iron cryptocurrency miners that connect victims to Kryptex, and infected servers are reused to scan for and compromise further vulnerable systems. More than 3,400 victim servers have been identified since April 2026, concentrated in the U.S. and Western Europe.
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- InfoStepSecurity Now Inventories AI Agent Skills in Your GitHub Repositories and on Developer Machines Similar attack · StepSecurity Blog
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database