Find notable cyber news and cases, enriched with sources, timelines, and signals.

PoeLLM malware mining and botnet expansion against AI/LLM infrastructure

Malware Activity
First reported
Last updated
Happening score
H score 60
1 unique sources, 1 articles

Summary

Hide ▲

The PoeLLM malware family is actively targeting exposed AI/LLM infrastructure to install cryptocurrency miners and expand a botnet, with more than 3,400 victim servers already identified. The activity has been running since April 2026 and is concentrated in the U.S. and Western Europe. Compromised hosts are reused as scanners and exploit servers, widening the pool of vulnerable systems. The malware hides its C2 address in a poem hosted in a GitHub repository.

Related Happenings

PoeLLM cryptomining and scanning malware activity against exposed AI servers

Malware Activity
H score62 First: 07.10.2026 18:04 Last: 07.10.2026 18:04 Sources 1

How related: Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

About this happening: PoeLLM is a new malware family in the Canto Incognito campaign that targets exposed AI/LLM infrastructure to deploy XMRig and Iron miners and grow a botnet...

Transparent Tribe Operation RapidRust campaign targeting India and Afghanistan

Campaign
H score38 First: 18.09.2026 18:24 Last: 18.09.2026 18:24 Sources 1

About this happening: The Transparent Tribe operation Operation RapidRust is sustaining active cyber attacks against government and defense organizations in India and Afghanistan, raising t...

Timeline

  1. 07.10.2026 18:33 1 articles · 2h ago

    GitHub repository begins hosting the poem that encodes PoeLLM C2 addresses

    Technical Analysis Update

    The PoeLLM operators began using a GitHub repository on April 13, 2026 to host the poem that hides the malware's command-and-control address, with later word changes in the poem used to derive new C2 locations for the botnet.

    Show sources
  2. 07.10.2026 18:33 2 articles · 2h ago

    Researchers identify PoeLLM malware targeting exposed AI and LLM infrastructure

    Initial Disclosure

    Lumen Black Lotus Labs identified PoeLLM as a new malware family used in the Canto Incognito campaign to target exposed AI and large language model infrastructure, install XMRig and Iron cryptocurrency miners, connect victims to Kryptex, and reuse compromised hosts as scanners and exploit servers to find additional vulnerable systems.

    Show sources