WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem

Network switches with status lights in a dark server rackAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

PoeLLM malware (software written to damage a system or steal from it) has assembled a sweeping botnet (a network of hijacked machines controlled by one operator), taking technical cues from a poem, according to CyberScoop. More than 3,400 servers have been compromised by malware that hides its infrastructure coordinates in a poem. Malware that takes technical cues from a poem to assemble a growing botnet by targeting open-source AI services has compromised more than 3,400 servers since April, Lumen Technologies’ Black Lotus Labs said in a report Wednesday.

The poem, which a threat actor (the person or group behind an attack) wrote and posted on a GitHub repository, seems innocuous but it’s driving a stealthy piece of malware researchers call PoeLLM. Four specific words extracted from the poem, which have been changed at least a dozen times, are converted into a command-and-control server address through a hard-coded dictionary embedded in the malware — a framework that bolsters PoeLLM’s resiliency.

Sources & evidence