MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-07 · via The Hacker News

Canto Incognito Campaign Uses PoeLLM Malware to Build Crypto-Mining Botnet from AI Servers

Image via The Hacker News
Image via The Hacker News

Researchers have detailed a financially motivated malware campaign called Canto Incognito that targets exposed AI and large language model systems. The malware, named PoeLLM, has infected more than 3,400 servers and installs cryptocurrency miners. The goal is to grow a botnet and generate illicit mining revenue.

Expanded Detail

The Canto Incognito operation is described as a campaign driven by financial gain. It seeks out AI and large language model systems that are reachable from the internet. The malware tied to it, PoeLLM, has reportedly compromised over 3,400 servers. After infection, it places cryptocurrency mining software on those machines. The operators' apparent aim is to enlarge a botnet and earn money through unauthorized mining.

Context

Organizations running exposed AI or LLM servers could face degraded performance, higher energy costs, and remediation burdens if PoeLLM infects them. Users of those systems may experience slower or less reliable service. The botnet's growth could add to illicit crypto-mining activity, potentially imposing indirect costs on the wider digital ecosystem. The campaign's financial motive suggests attackers may profit while affected parties bear operational and security consequences.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet.” Browse more stories.