Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PoeLLM Malware Targets AI Systems for Crypto Mining

PoeLLM Malware Targets AI Systems for Crypto Mining

Posted on October 7, 2026 By CWS

Cybersecurity experts have unveiled a novel malware named PoeLLM, which is actively exploiting artificial intelligence (AI) and large language model (LLM) infrastructures to deploy cryptocurrency miners. This operation is part of a financially driven initiative known as Canto Incognito, aiming to grow its botnet network.

Cryptocurrency Mining via Compromised Servers

The Canto Incognito campaign has been observed installing cryptocurrency miners such as XMRig and Iron. These miners connect to Kryptex, a cryptocurrency mining service based in Russia. According to a report from Lumen Black Lotus Labs, compromised servers are repurposed to become scanners and exploit servers, aiding in the expansion of the botnet by identifying additional vulnerable systems.

Innovative Command-and-Control Techniques

The malware uses a unique method to conceal its command-and-control (C2) address within a poem hosted on a GitHub repository. This repository saw its first update on April 13, 2026. Each new C2 setup involves minor changes to the poem, from which the malware extracts the address using specific keywords. This technique demonstrates the creative approach the threat actors employ to maintain their operations.

Targeting AI and LLM Deployments

The primary targets of these attacks are enterprise-level, internet-facing deployments, including LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances. The malware exploits these systems’ computational power for unauthorized cryptocurrency mining. Reports indicate that the malware has infected over 3,400 servers, with significant concentrations in the U.S. and Western Europe.

At its peak in mid-June, the campaign affected nearly 2,200 servers, with approximately 800 active daily. Recently, there has been increased activity towards SSH and other login portals, suggesting experimentation with distributed brute-force attacks, though the full capabilities of these attacks remain unclear.

Implications and Future Concerns

The campaign further leverages compromised systems to scan for similar vulnerabilities, sending HTTP POST requests to instruct identified targets to download the malware. Lumen Black Lotus Labs attributes these activities to an Italian-speaking threat actor, based on linguistic artifacts and network flow indicators.

The campaign’s end goal is to exploit known vulnerabilities in publicly exposed services to recruit them into a cryptocurrency mining botnet and transform some into scanners to widen the victim pool. As AI infrastructure continues to grow, it poses an increasingly attractive target due to its powerful hardware and potential data repositories, underscoring the need for enhanced security measures in these environments.

The Hacker News Tags:AI, Botnet, Canto Incognito, crypto-mining, Cryptojacking, Cybersecurity, Kryptex, LLM, Malware, PoeLLM

Post navigation

Previous Post: SonicWall Addresses Critical SMA1000 Vulnerabilities
Next Post: Hackers Breach Domain Registries for Unauthorized Certificates

Related Posts

CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises The Hacker News
Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices The Hacker News
DRILLAPP Backdoor Exploits Microsoft Edge in Ukraine DRILLAPP Backdoor Exploits Microsoft Edge in Ukraine The Hacker News
AI Memory Poisoning: The Threat of Hidden Prompts AI Memory Poisoning: The Threat of Hidden Prompts The Hacker News
North Korean Hackers Target Axios, Chrome Exploits, Fortinet Breaches North Korean Hackers Target Axios, Chrome Exploits, Fortinet Breaches The Hacker News
Cisco Releases Critical Patches for Security Flaws Cisco Releases Critical Patches for Security Flaws The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator
  • Malicious npm Packages Uncovered in Extensive Malware Campaign
  • Hackers Breach Domain Registries for Unauthorized Certificates
  • PoeLLM Malware Targets AI Systems for Crypto Mining
  • SonicWall Addresses Critical SMA1000 Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator
  • Malicious npm Packages Uncovered in Extensive Malware Campaign
  • Hackers Breach Domain Registries for Unauthorized Certificates
  • PoeLLM Malware Targets AI Systems for Crypto Mining
  • SonicWall Addresses Critical SMA1000 Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark