Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Scientists warn a popular vitamin D supplement may have a hidden downside

    October 8, 2026

    ‘A few are afraid of the chicks’: Preparing Thailand’s rescued leopard cats for life in the wild

    October 8, 2026

    Germany is right to rearm. But Europe has well-founded fears about that | Paul Taylor

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Scientists warn a popular vitamin D supplement may have a hidden downside
    • ‘A few are afraid of the chicks’: Preparing Thailand’s rescued leopard cats for life in the wild
    • Germany is right to rearm. But Europe has well-founded fears about that | Paul Taylor
    • Nana Patekar: Bollywood actor dies at 75 in Goa home
    • While VCs crowd into San Francisco, Endeavor Catalyst raises $320M for founders ‘elsewhere’
    • PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
    • Anthropic Launches Haiku 5.5: Its Cheapest and Fastest Claude Model Yet
    • Earth’s center is moving, and NASA just measured it
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 07, 2026Botnet / Cryptojacking

    Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.

    The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service.

    “Compromised hosts are reused to expand the botnet,” Lumen Black Lotus Labs said in a report shared with The Hacker News. “Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems.”

    The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a “creative” technique that hides the command-and-control (C2) address within a poem the threat actors wrote and hosted in a GitHub repository (“github[.]com/ejejejdfbbebe”). The first commit to the repository was on April 13, 2026.

    Cybersecurity

    “Each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words,” Ryan English, information security engineer at Lumen Technologies, told The Hacker News.

    The attacks have been primarily found to single out enterprise, internet-facing deployments such as LiteLLM and Gotenberg, as well as Gitea and Ivanti Sentry appliances.

    C2 Extraction Logic

    The targeting of these LLM instances is no coincidence as the intention is to abuse their compute power for illicit cryptocurrency mining. Evidence indicates that the malware has been active since April 2026, with more than 3400 victim servers identified so far. The infections are concentrated in the U.S. and Western Europe.

    “At the peak of operations in mid-June, the campaign involved almost 2,200 affected servers, with nearly 800 active per day,” the cybersecurity company said. “More recent traffic toward SSH and other login portals suggests experimentation with distributed brute-force attacks; that capability’s maturity remains uncertain.”

    Another notable aspect of the campaign is that it repurposes some of the compromised systems to scan the internet for similar instances, send an HTTP POST request to exposed ports on identified targets that instruct them to download the malware from the C2.

    Cybersecurity

    Lumen Black Lotus Labs has attributed the activity to an Italian-speaking threat actor with moderate confidence based on the presence of Italian-language artifacts and netflow indicators. The end goal of the campaign is to weaponize known vulnerabilities in publicly exposed services to enlist them into a cryptocurrency mining botnet and convert a subset of them into a scanner to expand the victim pool.

    “AI infrastructure is becoming an attractive target,” Lumen said. “Exposed AI/LLM services are valuable not only because of software vulnerabilities, but also because they may contain useful data and run on powerful hardware suitable for mining.”

    Botnet Crypto expand infects Malware Mining PoeLLM Servers
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    U.S. Investors Want To Up Their Crypto Holdings: Charles Schwab

    SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

    US government moves $470 million in seized crypto to Coinbase wallets, raising Bitcoin sale questions

    Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    Ransomware recovery CEO charged over secret ransom payments

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Scientists warn a popular vitamin D supplement may have a hidden downside

    October 8, 2026

    ‘A few are afraid of the chicks’: Preparing Thailand’s rescued leopard cats for life in the wild

    October 8, 2026

    Germany is right to rearm. But Europe has well-founded fears about that | Paul Taylor

    October 8, 2026

    Nana Patekar: Bollywood actor dies at 75 in Goa home

    October 8, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Scientists warn a popular vitamin D supplement may have a hidden downside

    October 8, 2026

    ‘A few are afraid of the chicks’: Preparing Thailand’s rescued leopard cats for life in the wild

    October 8, 2026

    Germany is right to rearm. But Europe has well-founded fears about that | Paul Taylor

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.