PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
What happened
PoeLLM malware (software written to damage a system or steal from it) has assembled a sweeping botnet (a network of hijacked machines controlled by one operator), taking technical cues from a poem, according to CyberScoop. More than 3,400 servers have been compromised by malware that hides its infrastructure coordinates in a poem. Malware that takes technical cues from a poem to assemble a growing botnet by targeting open-source AI services has compromised more than 3,400 servers since April, Lumen Technologies’ Black Lotus Labs said in a report Wednesday.
The poem, which a threat actor (the person or group behind an attack) wrote and posted on a GitHub repository, seems innocuous but it’s driving a stealthy piece of malware researchers call PoeLLM. Four specific words extracted from the poem, which have been changed at least a dozen times, are converted into a command-and-control server address through a hard-coded dictionary embedded in the malware — a framework that bolsters PoeLLM’s resiliency.
Sources & evidence
- CyberScoop Reporting source
PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem ↗
https://cyberscoop.com/poellm-malware-botnet-poem-lumen-black-lotus-labs/