{"slug": "poellm-malware-has-assembled-a-sweeping-botnet-taking-technical-cues-from-a-poem", "title": "PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem", "summary": "Lumen Technologies' Black Lotus Labs reported Wednesday that malware it calls PoeLLM has compromised more than 3,400 servers since April by targeting open-source AI services, using four words extracted from a GitHub-hosted poem as a dynamic lookup table to derive its command-and-control server address. Black Lotus Labs information security engineer Ryan English said the malware's C2 IP address is \"invisible outside of the victim's netflow,\" and that the botnet has grown by converting compromised servers into attackers and rotating C2 infrastructure. Researchers first encountered PoeLLM infrastructure in June during an investigation into a maximum-severity defect in Ivanti's Sentry secure mobile gateway, uncovering an exploit-scanning and cryptocurrency-mining botnet linked to compromised services including LiteLLM, Ollama, Gotenberg and Gitea.", "body_md": "# PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem\n\nMalware that takes technical cues from a poem to assemble a growing botnet by targeting open-source AI services has compromised more than 3,400 servers since April, Lumen Technologies’ Black Lotus Labs said in a report Wednesday.\n\nThe poem, which a threat actor wrote and posted on a GitHub repository, seems innocuous but it’s driving a stealthy piece of [malware](https://cyberscoop.com/tag/malware) researchers call PoeLLM. Four specific words extracted from the poem, which have been changed at least a dozen times, are converted into a command-and-control server address through a hard-coded dictionary embedded in the malware — a framework that bolsters PoeLLM’s resiliency.\n\n“The most interesting piece of the poem approach is that the IP address used for C2 communications is invisible outside of the victim’s netflow. In other malware samples, there might be a hard-coded fallback C2 address, or URL which points to an IP address written elsewhere on the internet,” Ryan English, information security engineer at Black Lotus Labs, told CyberScoop.\n\n“To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models,” he added. “There would be no reason for any security researcher to identify this poem as malicious — or know about the IP address hidden within it — unless they had access to the malware referencing it.”\n\nResearchers first encountered PoeLLM infrastructure in June during an investigation into a maximum-severity defect affecting Ivanti’s secure mobile gateway product, Sentry. That discovery uncovered a sweeping exploit-scanning and cryptocurrency-mining botnet linked to multiple compromised services and tools, including LiteLLM, Ollama, Gotenberg and Gitea.\n\nWhile “PoeLLM has been extremely successful in compromising multiple AI-related services at scale,” the threat actor’s achievements beyond exploit scanning and cryptomining remain under investigation, English said.\n\nThe malware contains functionality that can allow for remote code execution, potentially allowing a threat actor to abuse AI models on victim servers, along with public-facing services for downstream compromise, he added.\n\n“Through the growth of this botnet, the actor has effectively created a private army of AI-enabled proxies, which will continue to multiply and provide additional vectors for attack, credential theft, token abuse and more,” English said.\n\nThe botnet has continued to grow by converting compromised servers into attackers and shifting through C2 infrastructure, leaving fewer traces across the internet.\n\n“If one exploit server gets reported by the security community, the attacker can easily pivot and start proxying attacks through hundreds of other compromised victims,” English said.\n\nThe poem serves as a dynamic lookup table for this infrastructure rotation. When the malware retrieves the updated poem from GitHub, it extracts four specific words based on their positions relative to fixed text anchors within the verse. Each extracted word is then matched against a hard-coded dictionary in the malware, where individual words map to sets of IP addresses. The four numbers combine to form the current C2 server address. This means the threat actor can change the entire poem, and thus the C2 location, without updating the malware itself.\n\n“Many of the C2s used in this campaign were never detected on crowd-sourced security tools, indicating that this layer of obfuscation was very helpful in improving the resilience of a C2,” English said.\n\nFor instance, the first stanza of the poem, as it was observed last month, reads: “In the silent hum of driver, the machines begin to speak, each pulse of diode threading light through copper veins. We taught the dark to carry meaning, byte by byte — a language built from lightning, cold and clean.”\n\nThe malware extracts four specific words from the poem and matches each to a number in a hard-coded dictionary — for example, “driver” equals 92, “diode” equals 119, “decryption” equals 165, and “string” equals 74, combining to form the C2 address. When the threat actor changes the poem’s keywords, the malware automatically calculates a new C2 address without needing to update itself. This keeps the infrastructure invisible to network monitoring tools unless the malware code is directly analyzed.\n\nBlack Lotus Labs said the threat actor behind PoeLLM is likely Italian or speaks Italian. Researchers observed multiple comments in the malware code written in Italian and said the threat actor has relied on Italy-based servers for testing and C2 infrastructure.\n\nResearchers said they don’t know how many people are involved in the PoeLLM’s operation, and they haven’t observed any connections to other groups or campaigns.", "url": "https://wpnews.pro/news/poellm-malware-has-assembled-a-sweeping-botnet-taking-technical-cues-from-a-poem", "canonical_source": "https://cyberscoop.com/poellm-malware-botnet-poem-lumen-black-lotus-labs/", "published_at": "2026-10-07 15:00:00+00:00", "updated_at": "2026-10-07 15:21:46.655028+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-infrastructure", "ai-tools"], "entities": ["Lumen Technologies", "Black Lotus Labs", "PoeLLM", "Ryan English", "Ivanti", "Sentry", "LiteLLM", "Ollama"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/poellm-malware-has-assembled-a-sweeping-botnet-taking-technical-cues-from-a-poem", "markdown": "https://wpnews.pro/news/poellm-malware-has-assembled-a-sweeping-botnet-taking-technical-cues-from-a-poem.md", "text": "https://wpnews.pro/news/poellm-malware-has-assembled-a-sweeping-botnet-taking-technical-cues-from-a-poem.txt", "jsonld": "https://wpnews.pro/news/poellm-malware-has-assembled-a-sweeping-botnet-taking-technical-cues-from-a-poem.jsonld"}}