Threat Intelligence

PoeLLM Botnet Hijacks Exposed AI Servers to Mine Cryptocurrency

The Hacker News · 8 Oct 2026
Key Takeaway Check which AI, document-processing and code-hosting tools your business exposes to the internet, and restrict access or patch them promptly, since attackers are actively hunting for them.

Researchers at Lumen Black Lotus Labs have identified a financially motivated campaign, dubbed Canto Incognito, that targets exposed artificial intelligence and large language model (LLM) infrastructure. The attackers install cryptocurrency miners, including XMRig and Iron, and connect victims to Kryptex, a Russian mining service. Evidence suggests the malware has been active since April 2026, with more than 3,400 victim servers identified, mostly in the U.S. and Western Europe.

The malware, named PoeLLM, hides the address of its command-and-control server inside a poem hosted in a GitHub repository. According to Lumen's Ryan English, each time the attackers set up a new server they change a few words in the poem, and the malware works out the address from the key tied to those words. Targets are mainly enterprise, internet-facing deployments such as LiteLLM, Gotenberg, Gitea and Ivanti Sentry appliances. The attackers want the computing power of these systems for illicit mining.

The botnet also grows by reusing victims. Infected servers are turned into scanners and exploit servers that look for other vulnerable systems and instruct them to download the malware. At its mid-June peak, almost 2,200 servers were affected, with nearly 800 active per day. Researchers also saw recent traffic aimed at SSH and other login portals, which suggests experiments with distributed brute-force attacks, though how mature that capability is remains uncertain.

PoeLLM cryptomining botnet LLM security Lumen Black Lotus Labs

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.