Back to all news
Security

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

The Hacker News·October 7, 2026·1 min read
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

A new malware family called Canto Incognito has infected over 3,400 servers, targeting exposed AI and LLM infrastructure to deploy cryptocurrency miners and expand a botnet. The financially motivated campaign installs miners on compromised systems, leveraging AI infrastructure for illicit crypto mining. Researchers warn of the growing threat to unsecured AI and LLM deployments.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store