PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
Malware that takes technical cues from a poem to assemble a growing botnet by targeting open-source AI services has compromised more than 3,400 servers since April, Lumen Technologies’ Black Lotus Labs said in a report Wednesday.
The poem, which a threat actor wrote and posted on a GitHub repository, seems innocuous but it’s driving a stealthy piece of malware researchers call PoeLLM. Four specific words extracted from the poem, which have been changed at least a dozen times, are converted into a command-and-control server address through a hard-coded dictionary embedded in the malware — a framework that bolsters PoeLLM’s resiliency.
“The most interesting piece of the poem approach is that the IP address used for C2 communications is invisible outside of the victim’s netflow. In other malware samples, there might be a hard-coded fallback C2 address, or URL which points to an IP address written elsewhere on the internet,” Ryan English, information security engineer at Black Lotus Labs, told CyberScoop.
“To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models,” he added. “There would be no reason for any security researcher to identify this poem as malicious — or know about the IP address hidden within it — unless they had access to the malware referencing it.”
Researchers first encountered PoeLLM infrastructure in June during an investigation into a maximum-severity defect affecting Ivanti’s secure mobile gateway product, Sentry. That discovery uncovered a sweeping exploit-scanning and cryptocurrency-mining botnet linked to multiple compromised services and tools, including LiteLLM, Ollama, Gotenberg and Gitea.
While “PoeLLM has been extremely successful in compromising multiple AI-related services at scale,” the threat actor’s achievements beyond exploit scanning and cryptomining remain under investigation, English said.
The malware contains functionality that can allow for remote code execution, potentially allowing a threat actor to abuse AI models on victim servers, along with public-facing services for downstream compromise, he added.
“Through the growth of this botnet, the actor has effectively created a private army of AI-enabled proxies, which will continue to multiply and provide additional vectors for attack, credential theft, token abuse and more,” English said.
The botnet has continued to grow by converting compromised servers into attackers and shifting through C2 infrastructure, leaving fewer traces across the internet.
“If one exploit server gets reported by the security community, the attacker can easily pivot and start proxying attacks through hundreds of other compromised victims,” English said.
The poem serves as a dynamic lookup table for this infrastructure rotation. When the malware retrieves the updated poem from GitHub, it extracts four specific words based on their positions relative to fixed text anchors within the verse. Each extracted word is then matched against a hard-coded dictionary in the malware, where individual words map to sets of IP addresses. The four numbers combine to form the current C2 server address. This means the threat actor can change the entire poem, and thus the C2 location, without updating the malware itself.
“Many of the C2s used in this campaign were never detected on crowd-sourced security tools, indicating that this layer of obfuscation was very helpful in improving the resilience of a C2,” English said.
For instance, the first stanza of the poem, as it was observed last month, reads: “In the silent hum of driver, the machines begin to speak, each pulse of diode threading light through copper veins. We taught the dark to carry meaning, byte by byte — a language built from lightning, cold and clean.”
The malware extracts four specific words from the poem and matches each to a number in a hard-coded dictionary — for example, “driver” equals 92, “diode” equals 119, “decryption” equals 165, and “string” equals 74, combining to form the C2 address. When the threat actor changes the poem’s keywords, the malware automatically calculates a new C2 address without needing to update itself. This keeps the infrastructure invisible to network monitoring tools unless the malware code is directly analyzed.
Black Lotus Labs said the threat actor behind PoeLLM is likely Italian or speaks Italian. Researchers observed multiple comments in the malware code written in Italian and said the threat actor has relied on Italy-based servers for testing and C2 infrastructure.
Researchers said they don’t know how many people are involved in the PoeLLM’s operation, and they haven’t observed any connections to other groups or campaigns.