PoeLLM: malware attacks 3,400 AI servers to mine cryptocurrency
A campaign exploits exposed AI and LLM infrastructure to deploy cryptocurrency miners and expand a botnet. We analyze the risk for SMBs and how to protect yourself.

Cybersecurity researchers have warned about a new malware family, dubbed PoeLLM, that is infecting servers with exposed artificial intelligence (AI) infrastructure and large language models (LLM) on the internet. The goal is none other than to deploy cryptocurrency miners and expand the scale of a botnet. The campaign, financially motivated, has been named Canto Incognito and has already affected more than 3,400 servers, according to data published by The Hacker News.
The modus operandi is well known: attackers look for misconfigured systems or those with known vulnerabilities, access them, and install mining software. What is new here is the focus on AI and LLM environments, which are often deployed in a hurry and without adequate security measures. These servers usually have great computing capacity, which makes them a very attractive target for cybercriminals.
What does it mean for an SMB or an IT team?
If your company has started experimenting with AI, even on a small scale, this incident should set off all the alarms. You don't need a GPU cluster: a server with a language model accessible from the internet, a poorly protected API, or a container with default credentials is enough. Attackers don't discriminate by size; they look for any computing resource they can monetize.
The consequences can be serious: from excessive resource consumption (which drives up the cloud bill or degrades the service) to the theft of sensitive data passing through those models, not to mention reputational damage if the server is used for other illicit purposes. Furthermore, once inside, the attacker can move laterally and compromise other systems on the corporate network.
Recommendations to protect your AI infrastructure
At ForgeNEX we have long insisted that security cannot be an afterthought. These are the steps we recommend applying as soon as possible:
- Inventory and visibility: know exactly which servers, containers, and AI services you have exposed. You cannot protect what you don't know exists.
- Network segmentation: isolate AI environments from the rest of the critical infrastructure. If a server is compromised, the damage must be contained.
- Access management: apply the principle of least privilege. Review default credentials, API keys, and tokens. Rotate them periodically.
- Patching and updates: keep AI frameworks, libraries, and the operating system up to date. Many attacks exploit already known vulnerabilities.
- Resource monitoring: a sudden spike in CPU or GPU can be the first sign that someone is mining cryptocurrency on your servers. Configure alerts.
- Backups and response plan: make sure you have complete backups and a clear incident response procedure.
Also, if you are deploying AI agents, review how you manage data retrieval and the autonomy you grant. In a recent article we discussed how Infino unifies data retrieval for AI agents, a key piece to maintain control. It is also useful to rethink how much autonomy to grant without losing control in the SOC.
The context: a rising trend
This is not an isolated case. Recently we saw how GitLab fixed a critical 9.9 flaw in its self-hosted AI Gateway and how FortiMail suffered a critical zero-day. The conclusion is clear: the attack surface expands as we adopt AI, and attackers are rapidly adapting their techniques.
AI security is not a one-time project, but a continuous process that must be integrated into the life cycle of any development.
For an SMB, the recommendation is to start with the basics: do not expose AI services to the internet without strong authentication, segment the network, and monitor resource consumption. If you do not have a dedicated security team, consider relying on a managed service provider that can audit and protect your infrastructure.
At ForgeNEX we can help you assess your exposure and implement measures proportionate to your size and budget. AI offers enormous opportunities, but also risks that should not be ignored.
Source: The Hacker News. Analysis and adaptation: ForgeNEX.