PoeLLM is a stealthy malware campaign that has compromised more than 3,400 servers since April by targeting open-source AI services and using a poem on GitHub to dynamically generate its command-and-control infrastructure. Black Lotus Labs linked the botnet to exploit scanning, cryptomining, and possible remote code execution against services including Ivanti Sentry, LiteLLM, Ollama, Gotenberg, and Gitea. #PoeLLM #GitHub #Ivanti #Sentry #LiteLLM #Ollama #Gotenberg #Gitea #BlackLotusLabs
Keypoints
- PoeLLM has compromised more than 3,400 servers since April.
- The malware uses a poem on GitHub to derive its C2 server address.
- Its C2 infrastructure can change without updating the malware itself.
- The botnet has been tied to exploit scanning and cryptocurrency mining.
- Researchers linked the campaign to compromised AI-related services and Ivanti Sentry.
Read More: https://cyberscoop.com/poellm-malware-botnet-poem-lumen-black-lotus-labs/