DevelopingSecurity

PoeLLM malware targets exposed AI infrastructure in cryptomining campaign

Reports describe PoeLLM malware targeting exposed AI services and infrastructure in a cryptomining campaign. One source says the malware installs cryptocurrency miners and expands a botnet; another reports compromised servers are used as scanners and exploit launchpads.

Image: BleepingComputer

What we know

Reported by one source

  • The malware family, described by one source as PoeLLM, targets exposed AI and large language model infrastructure and is used to deploy cryptocurrency miners and expand a botnet. — The Hacker News
  • Compromised servers are used as scanners and exploit launchpads. — BleepingComputer
  • The campaign is dubbed Canto Incognito. — The Hacker News

Open questions

  • The supplied reports do not establish the scale of infections or provide further details about the campaign's targets and operations. — The Hacker News, BleepingComputer

Coverage 3 publishers

  1. BleepingComputer

    PoeLLM malware infects exposed AI servers in cryptomining attacks

  2. The Register

    Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers

  3. The Hacker News

    PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Articles stay on their publishers’ sites; each link opens the original.