WORLDTECH NEWS Global technology intelligence.Contact
โ† Back to WORLDTECH
Cybersecurity SINGLE SOURCE

Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers

Female IT professional examining data servers in a modern data center setting.
Illustrative photo.Photo by Christina Morillo on Pexels

What happened

Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The malware (software written to damage a system or steal from it) reading it, dubbed PoeLLM, breaks into exposed AI services and open-source tools, mines cryptocurrency on them and operates with them to hunt for new victims. The researchers call the campaign Canto Incognito and believe it is the work of an Italian-speaking threat actor (the person or group behind an attack) who appears to be in it โ€ฆ More โ†’ The post Cryptomining botnet (a network of hijacked machines controlled by one operator) hides C2 addresses in GitHub poem, infects over 3,400 servers appeared first on Help Net Security .

Sources & evidence