Canto Incognito Malware Targets Exposed AI and LLM Infrastructure, Infects 3,400+ Servers
Campaign deploys cryptocurrency miners on compromised systems, expanding botnet scale

Key Takeaways
- Canto Incognito malware campaign targets exposed AI and LLM infrastructure globally.
- Over 3,400 servers have been infected, with cryptocurrency miners deployed.
- The operation is financially motivated, aiming to expand botnet capacity for mining.
- Exposed AI/LLM endpoints are the primary attack vector.
Related Security News

Eight Malicious npm Packages Deliver Overlord RAT and Stealer in Supply Chain Campaign
Researchers from CloudSEK and Checkmarx have identified a supply chain malware campaign operating under the codename MALFEX. Eight malicious npm packages, published since August 2023, have been downloaded 40,767 times. The packages deliver Overlord RAT and an information stealer to compromised hosts. The activity is attributed to a lone threat actor. No CVEs are associated with the campaign, as the threat involves malicious packages distributed via the npm registry.




