Back to News
Cybersecurity

New PoeLLM Malware Targets AI Infrastructure to Expand Crypto Mining Operations

Researchers warn of a new malware targeting AI systems to deploy cryptocurrency miners across thousands of servers.

Cybersecurity experts have identified a new malware family, referred to as PoeLLM, that has compromised over 3,400 servers by targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructures. This financially motivated campaign, known as Canto Incognito, is primarily focused on installing cryptocurrency miners, thereby expanding the reach and scale of its botnet operations. The malware exploits vulnerabilities in systems that are not adequately secured, highlighting the urgent need for robust cybersecurity measures in the rapidly evolving AI landscape.

For businesses operating with AI technologies, the emergence of PoeLLM serves as a critical reminder of the vulnerabilities inherent in deploying advanced systems without adequate protection. Companies must prioritize securing their AI infrastructures against such threats by implementing best practices, including regular vulnerability assessments and patch management. In a broader context, this incident underscores the intersection of cybersecurity and AI, as attackers increasingly target these technologies for financial gain, necessitating a proactive approach to safeguarding digital assets and maintaining operational integrity.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/10/poellm-malware-infects-3400-servers-to.html)*