Le malware PoeLLM infecte plus de 3 400 serveurs pour étendre un botnet de crypto mining
Titre original : PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Alerte Publié 2026-10-07
Un nouveau malware nommé PoeLLM cible les infrastructures d'intelligence artificielle et les modèles de langage (LLM) exposés pour déployer des mineurs de cryptomonnaies. Cette campagne, baptisée Canto Incognito, a déjà infecté plus de 3 400 serveurs pour étendre un botnet à des fins financières. Si vous exposez des API ou des interfaces de modèles d'IA sur Internet, assurez-vous qu'elles sont correctement authentifiées et ne laissent pas d'accès non restreints à vos ressources système.
Extrait original (en anglais)
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including