
PoeLLM Malware Infected Over 3,400 AI Servers
PoeLLM malware has compromised over 3,400 exposed AI and LLM servers to mine crypto and expand its botnet, Lumen reports.
Security researchers from Lumen Black Lotus Labs are calling attention to a new malware family named PoeLLM that they say has already infected more than 3,400 internet-facing servers, mostly in the United States and Western Europe. The malware targets exposed artificial intelligence (AI) and large language model (LLM) systems, which are AI programs trained on huge amounts of text, then installs cryptocurrency miners, programs that use a computer's processing power to earn digital currency, such as XMRig and Iron, and connects the infected machines to Kryptex, a Russian cryptocurrency mining service. Lumen describes the financially motivated campaign as Canto Incognito, and its goal is to turn compromised servers into a botnet, a network of hijacked computers controlled remotely by the attacker.
The malware hides its command-and-control (C2) address, the server that sends orders to infected machines, inside a poem that the attackers wrote and hosted in a GitHub repository at github.com/ejejejdfbbebe. Ryan English, an information security engineer at Lumen Technologies, explained that each time the group sets up a new C2, it changes a few words in the poem. The malware then derives the new address from a key associated with those changed words. The first code commit to that repository took place on April 13, 2026.
Lumen reports that the campaign mainly singles out enterprise, internet-facing deployments such as LiteLLM and Gotenberg, as well as Gitea and Ivanti Sentry appliances. The targeting of these LLM instances is deliberate: the attackers want to abuse their compute power for illicit cryptocurrency mining. Evidence points to activity since April 2026, with more than 3,400 victim servers identified so far. At the peak of operations in mid-June, the campaign involved almost 2,200 affected servers, and nearly 800 were active each day.
Infected servers are also reused to expand the botnet. According to Lumen, compromised hosts are turned into scanners that search the internet for similar exposed systems, as well as exploit servers used to attack them. The malware sends an HTTP POST request, a standard way for a program to send data to a server, to exposed ports on identified targets, instructing those machines to download the malware from the C2. Lumen attributes the activity to an Italian-speaking threat actor with moderate confidence, based on Italian-language artifacts and netflow indicators, which are records of network traffic patterns. The end goal is to weaponize known vulnerabilities in publicly exposed services, enlist those machines into a cryptocurrency mining botnet, and convert a subset of them into scanners to grow the victim pool further.
Lumen also observes that more recent traffic toward SSH, a common protocol for secure remote login, and other login portals suggests experimentation with distributed brute-force attacks, where attackers try many passwords against many machines. The maturity of that capability remains uncertain. The company warns that AI infrastructure is becoming an attractive target, because exposed AI and LLM services are valuable not only for their software vulnerabilities but also because they may contain useful data and run on powerful hardware that is well suited to mining. For website owners and hosting providers, the report is a reminder that any public-facing service can become a target if it is not patched and access is not restricted. For teams operating internet-facing services like the ones targeted in this campaign, AEU-I, a security-first IT and infrastructure consulting service, can help review exposed systems and reduce their attack surface before attackers find them.
How to Protect Yourself
- If you run software that is reachable from the internet, such as a website dashboard or a code tool, install security updates as soon as they are released and turn on automatic updates where possible.
- Put management pages, admin panels, and remote access behind a private network or a VPN (a tool that makes your connection private) so they are not open to everyone online.
- Use a strong, unique password and two-factor authentication (a second one-time code) on every remote login to your hosting, server, or code repository.
- Check your server's processor usage for unexpected long spikes or unfamiliar processes named XMRig or Iron, and remove anything you did not install.
- If you do not need a service to be public, close the port or take the service offline to reduce the number of ways attackers can get in.
Terms Explained
- malware Harmful software that can damage a system, steal data, or give an attacker control.
- botnet A network of hijacked computers that an attacker controls remotely, often used to mine cryptocurrency or send spam.
- command-and-control (C2) The server that sends instructions to infected machines in a botnet.
- large language model (LLM) An artificial intelligence program trained on huge amounts of text to understand and generate human language.
- cryptocurrency miner Software that uses a computer's processing power to solve puzzles and earn digital money.
- netflow indicators Records of network traffic patterns that can reveal how data moves between computers and where it goes.
- exposed ports Network endpoints that are open to the public internet, letting outside computers connect to a service.