Skip to main content
Emerging ThreatsMalware & Ransomware

PoeLLM Malware Exploits Poem to Fuel Growing Botnet

A dimly lit server room with a central server displaying a GitHub page with a poem.

More than 3,400 servers have been compromised since April by a stealthy botnet that derives its command-and-control addresses from a poem posted on GitHub, Lumen Technologies’ Black Lotus Labs said in a report this week.

PoeLLM's poem-based C2 mechanism

The malware, which researchers call PoeLLM, uses a surprising lookup strategy: it downloads a seemingly innocuous poem from a GitHub repository, extracts four specific words based on their positions relative to fixed text anchors, and converts those words into an IP address via a hard-coded dictionary embedded in the malware. That dictionary maps individual words to numbers; the four resulting numbers combine to form the current command-and-control (C2) server address. As Black Lotus Labs’ Ryan English described the innovation, “The most interesting piece of the poem approach is that the IP address used for C2 communications is invisible outside of the victim’s netflow.”

Because the poem contains no links, no files to download and no readily identifiable malicious markers, English said “there would be no reason for any security researcher to identify this poem as malicious — or know about the IP address hidden within it — unless they had access to the malware referencing it.” The threat actor has changed the poem’s keywords at least a dozen times, allowing the operator to rotate C2 infrastructure without updating the malware itself.

Services and vulnerabilities targeted: Ivanti Sentry, LiteLLM, Ollama, Gotenberg and Gitea

Researchers first encountered PoeLLM infrastructure in June during an investigation into a maximum-severity defect affecting Ivanti’s secure mobile gateway product, Sentry. That discovery revealed a broader exploit-scanning and cryptocurrency-mining botnet tied to multiple compromised services and tools, including LiteLLM, Ollama, Gotenberg and Gitea.

Black Lotus Labs said the botnet has been “extremely successful in compromising multiple AI-related services at scale.” The malware contains functionality that can allow for remote code execution, which could let a threat actor abuse AI models on victim servers and use public-facing services for downstream compromise.

Botnet scale, persistence and operational behavior

Since April, PoeLLM has converted more than 3,400 compromised servers into nodes in its botnet, according to the Black Lotus Labs reporting. The actor has built resilience by shifting through C2 infrastructure and proxying attacks through infected machines; English warned that “If one exploit server gets reported by the security community, the attacker can easily pivot and start proxying attacks through hundreds of other compromised victims.”

Many of the C2s used in this campaign “were never detected on crowd-sourced security tools,” English said, crediting the poem-based lookup table with improving the campaign’s stealth. Through this growth, the actor has “effectively created a private army of AI-enabled proxies, which will continue to multiply and provide additional vectors for attack, credential theft, token abuse and more,” English added.

Attribution signals: code comments and Italy-based infrastructure

Black Lotus Labs reported signals suggesting the actor is likely Italian or speaks Italian: multiple comments in the malware code were written in Italian, and the actor has relied on Italy-based servers for testing and C2 infrastructure. Researchers also noted they do not know how many people are involved in the operation and have not observed connections between PoeLLM and other groups or campaigns.

What this means for technologists, affected enterprises, and adversaries

  • Technologists and security teams: The poem-based C2 shows that network monitoring alone may miss this layer of obfuscation; Black Lotus Labs’ findings underscore the value of malware code analysis to reveal hidden C2 logic and of monitoring AI-related services for signs of exploitation and unauthorized model abuse.
  • Affected enterprises and procurement leaders: Organizations running Ivanti Sentry, LiteLLM, Ollama, Gotenberg, Gitea or similar public-facing AI services should treat remote code execution and service compromise as immediate risks and prioritize patching, containment and forensic analysis when incidents occur.
  • Adversaries and threat actors: The campaign demonstrates a model for resilient C2 rotation and proxying through compromised AI-enabled servers; the actor’s ability to change C2 addresses by editing a public poem lowers operational friction for continuing the botnet without distributing new binaries.

Black Lotus Labs’ report leaves a clear and narrow set of open items: the actor’s broader motives beyond exploit-scanning and cryptocurrency mining remain under investigation, and researchers have not yet seen links to other groups. For defenders, the immediate task is practical and specific — analyze any suspicious binaries for the poem-to-IP mapping, hunt for infected AI-related services, and assume that reported exploit servers may be only the visible tip of a larger, rapidly mutable botnet.

Original CyberScoop story

PoeLLM Malware Exploits Poem to Fuel Growing Botnet | OSINTSights