PoeLLM malware mining and botnet expansion against AI/LLM infrastructure
Malware Activity
Summary
Hide ▲
Show ▼
The PoeLLM malware family is actively targeting exposed AI/LLM infrastructure to install cryptocurrency miners and expand a botnet, with more than 3,400 victim servers already identified. The activity has been running since April 2026 and is concentrated in the U.S. and Western Europe. Compromised hosts are reused as scanners and exploit servers, widening the pool of vulnerable systems. The malware hides its C2 address in a poem hosted in a GitHub repository.
Related Happenings
PoeLLM cryptomining and scanning malware activity against exposed AI servers
Malware Activity
H score62
First: 07.10.2026 18:04
Last: 07.10.2026 18:04
Sources 1
How related:
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.
About this happening:
PoeLLM is a new malware family in the Canto Incognito campaign that targets exposed AI/LLM infrastructure to deploy XMRig and Iron miners and grow a botnet...
PoeLLM cryptomining and scanning malware activity against exposed AI servers
Malware ActivityHow related: Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.
About this happening: PoeLLM is a new malware family in the Canto Incognito campaign that targets exposed AI/LLM infrastructure to deploy XMRig and Iron miners and grow a botnet...
Transparent Tribe Operation RapidRust campaign targeting India and Afghanistan
Campaign
H score38
First: 18.09.2026 18:24
Last: 18.09.2026 18:24
Sources 1
About this happening:
The Transparent Tribe operation Operation RapidRust is sustaining active cyber attacks against government and defense organizations in India and Afghanistan, raising t...
Transparent Tribe Operation RapidRust campaign targeting India and Afghanistan
CampaignAbout this happening: The Transparent Tribe operation Operation RapidRust is sustaining active cyber attacks against government and defense organizations in India and Afghanistan, raising t...
Timeline
-
07.10.2026 18:33 1 articles · 2h ago
GitHub repository begins hosting the poem that encodes PoeLLM C2 addresses
Technical Analysis UpdateThe PoeLLM operators began using a GitHub repository on April 13, 2026 to host the poem that hides the malware's command-and-control address, with later word changes in the poem used to derive new C2 locations for the botnet.
Show sources
- PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet — thehackernews.com — 07.10.2026 18:33
-
07.10.2026 18:33 2 articles · 2h ago
Researchers identify PoeLLM malware targeting exposed AI and LLM infrastructure
Initial DisclosureLumen Black Lotus Labs identified PoeLLM as a new malware family used in the Canto Incognito campaign to target exposed AI and large language model infrastructure, install XMRig and Iron cryptocurrency miners, connect victims to Kryptex, and reuse compromised hosts as scanners and exploit servers to find additional vulnerable systems.
Show sources
- PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet — thehackernews.com — 07.10.2026 18:33
- PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet — thehackernews.com — 07.10.2026 18:33