PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
- Posted on October 7, 2026
- By The Hacker News
- 1 Views
- 1 min read
Security researchers have uncovered a sophisticated malware campaign targeting vulnerable AI and machine learning infrastructure across thousands of servers. The PoeLLM malware, attributed to the Canto Incognito threat actor, has successfully compromised over 3,400 systems to establish a massive cryptocurrency mining operation. This coordinated attack exploits exposed LLM endpoints and inadequate security configurations, leveraging hijacked computational resources for illicit blockchain activities while simultaneously expanding the botnet's reach and capabilities.
Summary auto-generated by AI from the original publisher's content. Editorial standards.