PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem

PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
PoeLLM is a stealthy malware campaign that has compromised more than 3,400 servers since April by targeting open-source AI services and using a poem on GitHub to dynamically generate its command-and-control infrastructure. Black Lotus Labs linked the botnet to exploit scanning, cryptomining, and possible remote code execution against services including Ivanti Sentry, LiteLLM, Ollama, Gotenberg, and Gitea. #PoeLLM #GitHub #Ivanti #Sentry #LiteLLM #Ollama #Gotenberg #Gitea #BlackLotusLabs

Keypoints

  • PoeLLM has compromised more than 3,400 servers since April.
  • The malware uses a poem on GitHub to derive its C2 server address.
  • Its C2 infrastructure can change without updating the malware itself.
  • The botnet has been tied to exploit scanning and cryptocurrency mining.
  • Researchers linked the campaign to compromised AI-related services and Ivanti Sentry.

Read More: https://cyberscoop.com/poellm-malware-botnet-poem-lumen-black-lotus-labs/