Canto Incognito Campaign Uses PoeLLM Malware to Build Crypto-Mining Botnet from AI Servers

Researchers have detailed a financially motivated malware campaign called Canto Incognito that targets exposed AI and large language model systems. The malware, named PoeLLM, has infected more than 3,400 servers and installs cryptocurrency miners. The goal is to grow a botnet and generate illicit mining revenue.
The Canto Incognito operation is described as a campaign driven by financial gain. It seeks out AI and large language model systems that are reachable from the internet. The malware tied to it, PoeLLM, has reportedly compromised over 3,400 servers. After infection, it places cryptocurrency mining software on those machines. The operators' apparent aim is to enlarge a botnet and earn money through unauthorized mining.
Organizations running exposed AI or LLM servers could face degraded performance, higher energy costs, and remediation burdens if PoeLLM infects them. Users of those systems may experience slower or less reliable service. The botnet's growth could add to illicit crypto-mining activity, potentially imposing indirect costs on the wider digital ecosystem. The campaign's financial motive suggests attackers may profit while affected parties bear operational and security consequences.