Skip to content
MediumNewsLLM-specific

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Published
Record updated
View JSON

Summary

Lumen Black Lotus Labs reported a financially motivated campaign, dubbed Canto Incognito, that deploys a malware family it calls PoeLLM against exposed AI and LLM infrastructure. The malware installs XMRig and Iron cryptocurrency miners that connect victims to Kryptex, and infected servers are reused to scan for and compromise further vulnerable systems. More than 3,400 victim servers have been identified since April 2026, concentrated in the U.S. and Western Europe.