Full Report
More than 3,400 servers have been compromised by malware that hides its infrastructure coordinates in a poem. The post PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem appeared first on CyberScoop.
Analysis Summary
# Tool/Technique: PoeLLM
## Overview
PoeLLM is a sophisticated malware family and botnet framework that leverages a novel steganographic technique to hide its Command and Control (C2) infrastructure coordinates within an innocuous-looking poem hosted on a GitHub repository. The botnet primarily targets open-source AI services and servers, converting compromised hosts into a "private army" of proxies for exploit scanning, cryptocurrency mining, and potential downstream attacks on AI models.
## Technical Details
- **Type:** Malware family / Botnet Framework
- **Platform:** Linux/Unix servers (specifically those hosting AI services like Ollama, LiteLLM, Gitea, and Gotenberg)
- **Capabilities:** Infrastructure obfuscation via DGA-like (Domain Generation Algorithm) poem mapping, Remote Code Execution (RCE), Cryptomining, Proxying/Relay, and Exploit Scanning.
- **First Seen:** April 2026 (Initially reported October 2026)
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1190 - Exploit Public-Facing Application (Targeting Ivanti Sentry, Ollama, etc.)
- **TA0011 - Command and Control**
- T1584.005 - Compromise Infrastructure: Botnet
- T1071.001 - Application Layer Protocol: Web Protocols (GitHub-hosted poem)
- T1027.003 - Obfuscation: Steganography (Poem-to-IP mapping)
- **TA0005 - Defense Evasion**
- T1564 - Hide Artifacts
- **TA0040 - Impact**
- T1496 - Resource Hijacking (Cryptomining)
## Functionality
### Core Capabilities
- **Dynamic C2 Resolution:** The malware fetches a poem from a GitHub repository. It identifies four specific words based on their proximity to fixed text "anchors" within the poem.
- **Dictionary Mapping:** These four words are cross-referenced against a hard-coded internal dictionary. Each word maps to a specific octet, which are then combined to reconstruct a IPv4 address.
- **Botnet Proliferation:** Compromised servers are tasked with scanning the internet for new vulnerable AI-related services to expand the botnet.
- **Cryptomining:** Utilization of victim hardware resources for financial gain.
### Advanced Features
- **Stealth Infrastructure Rotation:** The threat actor can rotate C2 IP addresses simply by editing the poem on GitHub. Because the poem contains no code, URLs, or encrypted strings, it bypasses standard security scanners.
- **AI Service Exploitation:** Specifically designed to target and potentially manipulate LLM (Large Language Model) environments and public-facing AI proxies.
- **Invisible Netflow:** Because the C2 IP is generated in memory via the dictionary, the IP address does not appear in the malware binary’s strings or static analysis.
## Indicators of Compromise
- **File Names:** PoeLLM (Internal naming may vary)
- **Network Indicators:**
- `raw.githubusercontent[.]com` (Traffic to specific poem repositories)
- C2 IP Reconstruction Example: `92.119.165[.]74` (Defanged example based on "driver", "diode", "decryption", "string")
- **Behavioral Indicators:**
- High CPU usage (Cryptomining)
- Unexpected outbound connections from AI services (Ollama, LiteLLM) to GitHub.
- Outbound scanning activity on ports associated with Gitea or Ivanti.
## Associated Threat Actors
- **Unidentified Actor:** Likely Italian-speaking or based in Italy (based on Italian language comments in the source code and use of Italian testing infrastructure).
## Detection Methods
- **Behavioral Detection:** Monitor for AI-related service processes (e.g., `ollama`, `litellm`) initiating outbound connections to GitHub or unknown external IPs.
- **Memory Analysis:** Scan for the hard-coded dictionary of words used for IP mapping within running processes.
- **Network Monitoring:** Alert on persistent traffic to specific GitHub raw content URLs that lack associated development activity.
## Mitigation Strategies
- **Patch Management:** Immediate patching of Ivanti Sentry and ensuring open-source AI tools (Ollama, Gitea) are updated to the latest secure versions.
- **Network Segmentation:** Isolate AI research and production servers from the broader internet; use egress filtering to restrict outbound traffic to only necessary APIs.
- **Access Control:** Implement strong authentication and API keys for LiteLLM and Ollama interfaces to prevent unauthorized remote execution.
## Related Tools/Techniques
- **Dead Drop Resolvers:** Similar to using Twitter/X or Reddit for C2, but uses natural language processing cues (the poem) rather than encoded strings.
- **Living off trusted sites (LOTS):** Leveraging GitHub for infrastructure resilience.