PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
PoeLLM malware has compromised over 3,400 servers, encoding its command-and-control address in a GitHub poem.
Lumen Technologies’ Black Lotus Labs said PoeLLM malware has compromised more than 3,400 servers since April by targeting exposed services including LiteLLM, Ollama, Gotenberg, and Gitea. The malware reads a poem on GitHub and maps four words through a hard-coded dictionary to assemble its command-and-control IP, so operators can rotate infrastructure without updating implants. The botnet conducts exploit scanning and cryptocurrency mining and can run remote code, which researchers say could abuse AI models on victim servers. Italian-language comments and Italy-based servers suggest an Italian-speaking operator, with no observed links to known groups.
- More than 3,400 servers compromised since April.
- C2 address is derived from four words in a GitHub poem.
- Targets include LiteLLM, Ollama, Gotenberg, and Gitea.
- Used for exploit scanning and cryptomining, with remote code execution capability.
- Code comments and servers suggest an Italian-speaking operator.
Full article974 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
More than 3,400 servers have been compromised by malware that hides its infrastructure coordinates in a poem.
Listen to this article
0:00
Learn more.
Malware that takes technical cues from a poem to assemble a growing botnet by targeting open-source AI services has compromised more than 3,400 servers since April, Lumen Technologies’ Black Lotus Labs said in a report Wednesday.
The poem, which a threat actor wrote and posted on a GitHub repository, seems innocuous but it’s driving a stealthy piece of malware researchers call PoeLLM. Four specific words extracted from the poem, which have been changed at least a dozen times, are converted into a command-and-control server address through a hard-coded dictionary embedded in the malware — a framework that bolsters PoeLLM’s resiliency.
“The most interesting piece of the poem approach is that the IP address used for C2 communications is invisible outside of the victim’s netflow. In other malware samples, there might be a hard-coded fallback C2 address, or URL which points to an IP address written elsewhere on the internet,” Ryan English, information security engineer at Black Lotus Labs, told CyberScoop.
“To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models,” he added. “There would be no reason for any security researcher to identify this poem as malicious — or know about the IP address hidden within it — unless they had access to the malware referencing it.”
Researchers first encountered PoeLLM infrastructure in June during an investigation into a maximum-severity defect affecting Ivanti’s secure mobile gateway product, Sentry. That discovery uncovered a sweeping exploit-scanning and cryptocurrency-mining botnet linked to multiple compromised services and tools, including LiteLLM, Ollama, Gotenberg and Gitea.
While “PoeLLM has been extremely successful in compromising multiple AI-related services at scale,” the threat actor’s achievements beyond exploit scanning and cryptomining remain under investigation, English said.
The malware contains functionality that can allow for remote code execution, potentially allowing a threat actor to abuse AI models on victim servers, along with public-facing services for downstream compromise, he added.
“Through the growth of this botnet, the actor has effectively created a private army of AI-enabled proxies, which will continue to multiply and provide additional vectors for attack, credential theft, token abuse and more,” English said.
The botnet has continued to grow by converting compromised servers into attackers and shifting through C2 infrastructure, leaving fewer traces across the internet.
“If one exploit server gets reported by the security community, the attacker can easily pivot and start proxying attacks through hundreds of other compromised victims,” English said.
The poem serves as a dynamic lookup table for this infrastructure rotation. When the malware retrieves the updated poem from GitHub, it extracts four specific words based on their positions relative to fixed text anchors within the verse. Each extracted word is then matched against a hard-coded dictionary in the malware, where individual words map to sets of IP addresses. The four numbers combine to form the current C2 server address. This means the threat actor can change the entire poem, and thus the C2 location, without updating the malware itself.
“Many of the C2s used in this campaign were never detected on crowd-sourced security tools, indicating that this layer of obfuscation was very helpful in improving the resilience of a C2,” English said.
For instance, the first stanza of the poem, as it was observed last month, reads: “In the silent hum of driver, the machines begin to speak, each pulse of diode threading light through copper veins. We taught the dark to carry meaning, byte by byte — a language built from lightning, cold and clean.”
The malware extracts four specific words from the poem and matches each to a number in a hard-coded dictionary — for example, “driver” equals 92, “diode” equals 119, “decryption” equals 165, and “string” equals 74, combining to form the C2 address. When the threat actor changes the poem’s keywords, the malware automatically calculates a new C2 address without needing to update itself. This keeps the infrastructure invisible to network monitoring tools unless the malware code is directly analyzed.
Black Lotus Labs said the threat actor behind PoeLLM is likely Italian or speaks Italian. Researchers observed multiple comments in the malware code written in Italian and said the threat actor has relied on Italy-based servers for testing and C2 infrastructure.
Researchers said they don’t know how many people are involved in the PoeLLM’s operation, and they haven’t observed any connections to other groups or campaigns.
Latest Podcasts
Government
Here’s how experts think CISA should tell agencies to protect OT
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
As AI world debates security, NVIDIA releases open source tools for agents
Technology
Threats
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
AI policy circles targeted in China-linked phishing operation
WaterISAC reckons with range of threats after summer of cyberattacks
Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
Policy
Wiretapping change sparks big privacy fight in the Golden State
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks