TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39533 245
🤖 PoeLLM Malware Expands Cryptojacking Footprint

PoeLLM has reportedly infected more than 3,400 servers to grow a crypto-mining botnet, with compromised infrastructure repurposed for sustained illicit mining activity. The campaign, outlined in PoeLLM malware coverage, centers on server-side compromise at scale rather than endpoint delivery.

The server count indicates a mature monetization operation with enough distributed capacity to absorb takedowns and maintain output. For defenders, the key signal is not novelty but scale: broad server exposure can be converted directly into resilient mining throughput and persistent unauthorized resource consumption.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 9, 2026🔍 FakeGit reactivates at scale on GitHub FakeGit has resumed activity with 17,610 malicio…
  2. Oct 9, 2026🔍 Cisco flags five critical NX-OS flaws on Nexus switches Cisco has issued advisories for…
  3. Oct 9, 2026🔍 Low-cost Android phones found shipping with firmware-level malware Bitdefender’s Midnig…
  4. Oct 9, 2026🔍 UAC-0099 deploys ASHVEIN RAT against Ukrainian government staff UAC-0099 is targeting U…
  5. Oct 9, 2026📡 Ukrainian strike disables Yandex cloud zone Yandex says its ru-central1-b availability…
  6. Oct 9, 2026🔍 Shai-Hulud hits AI tooling via Tensorlake SDK A malicious release of Tensorlake’s SDK v…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →