negativeSYS.SOURCE: The Hacker News• 2026-10-07T21:03:51+05:30
PoeLLM Malware Exploits AI Infrastructure to Expand Crypto Mining Botnet
PoeLLM malware targets exposed AI/LLM infrastructure to deploy cryptocurrency miners, using a poem-based technique to hide command-and-control addresses. The campaign has infected over 3,400 servers, expanding a crypto mining botnet while exploiting vulnerabilities in enterprise systems.
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.
The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including
*** END OF TRANSMISSION ***