VMTech
Discuss a project →

PoeLLM Campaign Enlists Exposed AI Servers for Crypto Mining

PoeLLM Campaign Enlists Exposed AI Servers for Crypto Mining

Cybersecurity researchers have identified a malware family called PoeLLM that has infected more than 3,400 servers since April 2026 in a campaign designed to build a cryptocurrency-mining botnet. Lumen Black Lotus Labs tracks the financially motivated activity as Canto Incognito, which has targeted exposed artificial intelligence and large language model infrastructure alongside other internet-facing enterprise services.

The operation installs cryptocurrency miners including XMRig and Iron and connects infected machines to Kryptex, a Russian cryptocurrency mining service. Lumen said the campaign reached almost 2,200 affected servers at its mid-June peak, with nearly 800 active servers per day. Victims have been concentrated in the United States and Western Europe.

Exposed AI services become mining infrastructure

The campaign has primarily singled out internet-facing deployments of LiteLLM and Gotenberg, as well as Gitea and Ivanti Sentry appliances. The selection of LLM-related systems is deliberate: they may run the powerful hardware needed for mining and can also hold useful data.

Attackers weaponize known vulnerabilities in publicly exposed services to enroll systems in the botnet. Rather than using every victim solely for mining, the operators repurpose a subset as scanners and exploit servers. These compromised hosts search for similar exposed systems and send HTTP POST requests to open ports, directing identified targets to download malware from the command-and-control infrastructure.

A poem hides the command-and-control address

PoeLLM received its name from an unusual command-and-control concealment method. The operators host a poem in a GitHub repository, whose first commit was made on April 13, 2026. The malware derives the command-and-control address from key words in that poem.

When the operators establish a new command-and-control server, they change a small number of words. Ryan English, an information security engineer at Lumen Technologies, said the malware uses the key associated with those changed words to derive the new address. This approach allows the campaign to alter its infrastructure without embedding a fixed destination in the malware.

Expansion and access risks remain in view

Lumen Black Lotus Labs attributed the activity to an Italian-speaking threat actor with moderate confidence, citing Italian-language artifacts and netflow indicators. More recent traffic to SSH and other login portals may indicate experimentation with distributed brute-force attacks, although Lumen said the maturity of that capability remains uncertain.

For businesses operating AI, LLM or related public-facing services, the campaign underlines the need to identify internet-exposed deployments, remediate known vulnerabilities and limit unnecessary access to administration and login portals. Systems with substantial compute capacity can be attractive targets not only because of software weaknesses, but also because their resources can be diverted into a mining and botnet-expansion operation.

#cybersecurity#malware#cryptojacking#aisecurity
Open analytics
On the site 0 views
min read 3 07.10.2026
Instagram

PoeLLM Campaign Enlists Exposed AI Servers for Crypto Mining

Open the post on Instagram ↗