PoeLLM Malware Uses GitHub Poem to Direct Botnet Across 3,400 Servers

Cryptomining operation targets exposed AI inference tools and updates its command infrastructure through changes to four words in a public verse.

Lumen's Black Lotus Labs has identified a cryptomining campaign that has already placed more than 3,400 servers under its control. The operators hide their command-and-control addresses inside a public GitHub poem and rotate those addresses by editing just four words in the verse, a tactic that has been executed eleven times so far.

The news

The malware, named PoeLLM by the researchers, focuses on internet-facing instances of LiteLLM and Ollama. These tools let teams run large language models locally with minimal setup. When left open without authentication, they give attackers an immediate path to install mining software and maintain long-term access. The poem-based lookup replaces the usual hard-coded domains or single fallback servers that defenders have learned to block.

Context

LiteLLM acts as a proxy layer for multiple model providers, while Ollama packages model execution into a simple local service. Both see frequent use in development and internal testing environments. In those settings, administrators often expose the management ports to speed up iteration and then forget to restrict them later. Once PoeLLM reaches such a host, it drops a miner and begins polling the GitHub repository on a schedule. Each time the operators alter the four designated words, the new values encode fresh IP addresses or domains. Infected machines pick up the changes automatically and migrate without any update to the binary itself.

Black Lotus Labs tracked eleven distinct updates to the poem during the campaign. The pattern has remained consistent, indicating the operators treat the public file as a stable, low-maintenance directory rather than a disposable channel. The majority of the 3,400 compromised machines matched the fingerprint of default LiteLLM or Ollama installations.

Detail

The poem itself functions as a living index. Four specific words inside the verse carry the current infrastructure data in encoded form. When the operators decide to move the botnet, they publish a new commit that changes only those words. Infected hosts parse the updated text, decode the addresses, and switch endpoints. This approach spreads the location information across a repository that any defender can read, yet it forces continuous monitoring because the signal changes at irregular intervals.

Traditional botnets that rely on a fixed list of domains or a single fast-flux provider present a narrower set of indicators. PoeLLM distributes its signal across ordinary-looking text commits, which reduces the value of simple blocklists. The same four-word mechanism has persisted across multiple infrastructure rotations, showing that the operators have not needed to push new malware samples to adapt.

Why it matters

Exposed AI tooling now supplies attackers with both compute resources and a ready-made persistence layer. Teams deploy these services for quick experiments, leave the ports open, and create durable footholds that require only a public text file to steer. The PoeLLM campaign demonstrates how little additional effort is needed once initial access exists: the repository stays visible, the changes stay small, and the infected hosts stay synchronized without further binaries. Until operators of LiteLLM and Ollama instances close unnecessary exposure or add authentication by default, the same low-friction pattern will continue to attract mining operations and other payloads that prize cheap, always-on servers.

---

Sources:

No comments yet