Cybersecurity experts have unveiled a novel malware named PoeLLM, which is actively exploiting artificial intelligence (AI) and large language model (LLM) infrastructures to deploy cryptocurrency miners. This operation is part of a financially driven initiative known as Canto Incognito, aiming to grow its botnet network.
Cryptocurrency Mining via Compromised Servers
The Canto Incognito campaign has been observed installing cryptocurrency miners such as XMRig and Iron. These miners connect to Kryptex, a cryptocurrency mining service based in Russia. According to a report from Lumen Black Lotus Labs, compromised servers are repurposed to become scanners and exploit servers, aiding in the expansion of the botnet by identifying additional vulnerable systems.
Innovative Command-and-Control Techniques
The malware uses a unique method to conceal its command-and-control (C2) address within a poem hosted on a GitHub repository. This repository saw its first update on April 13, 2026. Each new C2 setup involves minor changes to the poem, from which the malware extracts the address using specific keywords. This technique demonstrates the creative approach the threat actors employ to maintain their operations.
Targeting AI and LLM Deployments
The primary targets of these attacks are enterprise-level, internet-facing deployments, including LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances. The malware exploits these systems’ computational power for unauthorized cryptocurrency mining. Reports indicate that the malware has infected over 3,400 servers, with significant concentrations in the U.S. and Western Europe.
At its peak in mid-June, the campaign affected nearly 2,200 servers, with approximately 800 active daily. Recently, there has been increased activity towards SSH and other login portals, suggesting experimentation with distributed brute-force attacks, though the full capabilities of these attacks remain unclear.
Implications and Future Concerns
The campaign further leverages compromised systems to scan for similar vulnerabilities, sending HTTP POST requests to instruct identified targets to download the malware. Lumen Black Lotus Labs attributes these activities to an Italian-speaking threat actor, based on linguistic artifacts and network flow indicators.
The campaign’s end goal is to exploit known vulnerabilities in publicly exposed services to recruit them into a cryptocurrency mining botnet and transform some into scanners to widen the victim pool. As AI infrastructure continues to grow, it poses an increasingly attractive target due to its powerful hardware and potential data repositories, underscoring the need for enhanced security measures in these environments.
