Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Canto Incognito Malware Family: A Threat to AI Infrastructure and the Expanding Cryptojacking Botnet




A new and sophisticated malware family, dubbed Canto Incognito, has been discovered targeting exposed AI and LLM infrastructure for illicit cryptocurrency mining. With more than 3,400 victim servers identified, the malware has been linked to an Italian-speaking threat actor with moderate confidence. The Canto Incognito malware family represents a significant threat to AI infrastructure and the expanding cryptojacking botnet, highlighting the growing importance of cybersecurity measures to protect these vulnerable systems.

  • The Canto Incognito malware family targets exposed AI and LLM infrastructure with the aim of deploying cryptocurrency miners and expanding a botnet.
  • The malware installs various cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service.
  • The malware exploits known vulnerabilities in publicly exposed services to enlist them into a cryptocurrency mining botnet and convert some into scanners to expand the victim pool.
  • The financially motivated campaign has compromised hosts, reused them to expand the botnet, and turned infected servers into scanners and exploit servers.
  • The malware, codenamed PoeLLM, hides the command-and-control address within a poem and changes it each time a new C2 address is set up.
  • The targeting of AI infrastructure is not a coincidence, but rather an attempt to abuse compute power for illicit cryptocurrency mining.
  • The campaign involves a significant number of infected servers, with over 3,400 victim servers identified, and has been active since April 2026.
  • The malware has shown adaptability and persistence, repurposing compromised systems to scan the internet for similar instances and send HTTP POST requests to download the malware.
  • The activity is attributed to an Italian-speaking threat actor with moderate confidence based on the presence of Italian-language artifacts and netflow indicators.



  • The cybersecurity landscape has recently witnessed the emergence of a new and sophisticated malware family, dubbed Canto Incognito. This malicious entity has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with the primary aim of deploying cryptocurrency miners and further expanding the scale of the botnet.

    The Canto Incognito malware family has been found to install various cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service. This malicious activity is not limited to the installation of cryptocurrency miners but also involves the exploitation of known vulnerabilities in publicly exposed services to enlist them into a cryptocurrency mining botnet and convert a subset of them into a scanner to expand the victim pool.

    According to Lumen Black Lotus Labs, the financially motivated campaign behind the Canto Incognito malware family has been observed to compromise hosts and reuse them to expand the botnet. Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems.

    The malware distributed as part of the Canto Incognito campaign has been codenamed PoeLLM due to its unique technique of hiding the command-and-control (C2) address within a poem the threat actors wrote and hosted in a GitHub repository. This technique involves changing a few words in the poem each time a new C2 address is set up, and the malware derives the address from the key associated with those words.

    The targeting of AI infrastructure by the Canto Incognito malware family is not a coincidence. The intention is to abuse the compute power of these LLM instances for illicit cryptocurrency mining. Evidence indicates that the malware has been active since April 2026, with more than 3,400 victim servers identified so far. The infections are concentrated in the U.S. and Western Europe.

    At the peak of operations in mid-June, the campaign involved almost 2,200 affected servers, with nearly 800 active per day. This indicates the scale and sophistication of the Canto Incognito malware family. More recent traffic toward SSH and other login portals suggests experimentation with distributed brute-force attacks; the maturity of this capability remains uncertain.

    Another notable aspect of the campaign is that it repurposes some of the compromised systems to scan the internet for similar instances, send an HTTP POST request to exposed ports on identified targets that instruct them to download the malware from the C2. This behavior highlights the adaptability and persistence of the Canto Incognito malware family.

    Lumen Black Lotus Labs has attributed the activity to an Italian-speaking threat actor with moderate confidence based on the presence of Italian-language artifacts and netflow indicators. The end goal of the campaign is to weaponize known vulnerabilities in publicly exposed services to enlist them into a cryptocurrency mining botnet and convert a subset of them into a scanner to expand the victim pool.

    AI infrastructure is becoming an attractive target for malicious actors due to its valuable software vulnerabilities and powerful hardware. Exposed AI/LLM services are not only valuable because of software vulnerabilities but also because they may contain useful data. The Canto Incognito malware family represents a significant threat to AI infrastructure and the expanding cryptojacking botnet.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Canto-Incognito-Malware-Family-A-Threat-to-AI-Infrastructure-and-the-Expanding-Cryptojacking-Botnet-ehn.shtml

  • https://thehackernews.com/2026/10/poellm-malware-infects-3400-servers-to.html


  • Published: Wed Oct 7 12:39:40 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us