
What we know
Reported by one source
- The malware family, described by one source as PoeLLM, targets exposed AI and large language model infrastructure and is used to deploy cryptocurrency miners and expand a botnet. — The Hacker News
- Compromised servers are used as scanners and exploit launchpads. — BleepingComputer
- The campaign is dubbed Canto Incognito. — The Hacker News
Open questions
- The supplied reports do not establish the scale of infections or provide further details about the campaign's targets and operations. — The Hacker News, BleepingComputer
Coverage 3 publishers
-
PoeLLM malware infects exposed AI servers in cryptomining attacks
-
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
-
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Articles stay on their publishers’ sites; each link opens the original.