
PoeLLM Malware Hides C2 Addresses in GitHub Poem, Compromises Over 3,400 Servers
Lumen Technologies' Black Lotus Labs says the PoeLLM botnet has compromised more than 3,400 servers since April by targeting open-source AI services, using a poem on GitHub to hide its command-and-control infrastructure.
A Poem as a Command-and-Control Channel
Researchers at Lumen Technologies' Black Lotus Labs have documented a malware campaign called PoeLLM that uses a poem posted on GitHub to direct compromised machines to its command-and-control servers. According to a report published Wednesday, the malware has compromised more than 3,400 servers since April by targeting open-source AI services.
The poem appears innocuous and contains no links, downloadable files, or encrypted text. The malware extracts four specific words from the verse based on their positions relative to fixed text anchors, then matches each word against a hard-coded dictionary where individual words map to sets of IP addresses. The four resulting numbers combine to form the current command-and-control address. The threat actor has changed the selected words at least a dozen times, allowing the infrastructure to rotate without updating the malware itself.
Targeting AI Services at Scale
Researchers first encountered PoeLLM infrastructure in June while investigating a maximum-severity defect affecting Ivanti's secure mobile gateway product, Sentry. The discovery uncovered an exploit-scanning and cryptocurrency-mining botnet linked to multiple compromised services and tools, including LiteLLM, Ollama, Gotenberg, and Gitea.
Black Lotus Labs said the malware contains functionality that enables remote code execution, which could allow the threat actor to abuse AI models running on victim servers along with public-facing services for further compromise. The threat actor behind PoeLLM is likely Italian or speaks Italian, based on multiple comments written in Italian found in the malware code and the use of Italy-based servers for testing and command-and-control infrastructure. Researchers have not observed connections to other groups or campaigns and do not know how many people are involved in the operation.
Infrastructure Designed to Evade Detection
Because the command-and-control address is derived only on the victim's machine, it remains invisible in network flow data to outside observers. Many of the command-and-control servers used in the campaign were never detected on crowd-sourced security tools, which the researchers said indicates the obfuscation layer significantly improved the resilience of the infrastructure.
As the botnet grows, compromised servers are converted into attackers that proxy scans through hundreds of other victims, leaving fewer traces across the internet. Black Lotus Labs described the result as a private army of AI-enabled proxies that will continue to multiply and provide additional vectors for attacks, credential theft, and token abuse.
Sources: The Register · Cyberscoop · The Hacker News
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.