Particle.news

Poem‑Driven PoeLLM Botnet Compromises More Than 3,400 AI Servers

Black Lotus Labs says the poem lookup lets the operator rotate hidden command servers to repurpose infected AI hosts into miners and scanners.

Overview

  • Black Lotus Labs reported Wednesday that PoeLLM has infected more than 3,400 servers since April and remains active with infrastructure that continues to change.
  • The malware derives its command‑and‑control IP by extracting four words from a GitHub‑hosted poem and mapping those words through a hard‑coded dictionary to form an IPv4 address.
  • Researchers found PoeLLM installs XMRig and Iron miners and links victims to the Kryptex mining service while also keeping a remote shell that can enable remote code execution on compromised hosts.
  • Compromised servers are reused as scanners and exploit launchpads to find more exposed AI/LLM services such as LiteLLM, Ollama, Gotenberg, Gitea and Ivanti Sentry, helping the botnet expand and stay resilient.
  • Defenders should patch affected products, limit public exposure of AI services, restrict access to trusted IPs, and check logs against the IoCs published by Black Lotus Labs because infected hosts can be used for broader abuse and credential theft.