PoeLLM malware infects exposed AI servers in cryptomining attacks
Summary
A new cryptomining campaign is leveraging malware named PoeLLM to compromise exposed AI servers. The malware turns these infected servers into scanners to find other vulnerable AI services and then uses them as launchpads to deploy the cryptomining payload.
IFF Assessment
FOE
This malware targets and exploits vulnerable AI servers, which is detrimental to defenders by expanding the attack surface and compromising resources.
Defender Context
This highlights a growing trend of threat actors exploiting AI infrastructure. Defenders need to prioritize securing AI servers and services, ensuring they are not exposed to the internet and are properly patched and configured to prevent similar infections.