PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Summary
A new malware family, named PoeLLM and associated with the Canto Incognito campaign, is targeting exposed AI and LLM infrastructure. The malware's primary goal is to deploy cryptocurrency miners and enlarge an existing botnet by infecting over 3,400 servers.
IFF Assessment
FOE
This malware campaign is designed to compromise infrastructure and exploit resources for financial gain, which is detrimental to defenders.
Defender Context
The emergence of malware specifically targeting AI and LLM infrastructure highlights a growing attack surface that defenders must monitor. Organizations deploying these technologies need to ensure their infrastructure is properly secured against unauthorized access and the deployment of malicious software.