Security researchers report that PoeLLM malware is being used in a financially motivated campaign that targets exposed AI and large language model (LLM) infrastructure. Multiple outlets say the activity installs cryptocurrency miners and turns compromised servers into parts of a botnet, with the goal of increasing mining capacity.
The campaign, described under names such as “Canto Incognito,” is said to include components that scan for additional targets and use compromised systems as “exploit launchpads.” CyberScoop adds that the malware hides infrastructure-related information in a poem-like structure, a technique researchers cite as a notable signature. Other coverage emphasizes the focus on exposed AI services and the way the malware leverages them for further compromise, rather than targeting end users directly.
While the outlets agree on the overall mechanics—botnet expansion, scanning, and cryptomining—the reporting highlights different technical framing, including the campaign name and the “poem” method for concealing command-and-control or infrastructure details.