Lumen's Black Lotus Labs said on Wednesday that PoeLLM malware has taken over more than 3,400 servers since April, CyberScoop reported. It targets open-source AI services. The malware learns where its control server is, the machine that sends it orders, from a poem on GitHub. A threat actor wrote it. The malware pulls four words from the verse and looks each up in a built-in word list. Each word stands for a number, and the four numbers form the address. The key words have changed at least a dozen times.
Researchers first found PoeLLM's setup in June, while studying a maximum-severity flaw in Ivanti's Sentry gateway. That led to a botnet that scans for flaws and mines cryptocurrency, tied to compromised services including LiteLLM, Ollama, Gotenberg and Gitea. The malware can run code remotely, which could let the actor misuse AI models on victim servers. Its aims beyond scanning and mining are still under investigation. The lab does not know how many people run it.
The attacker can move the control server by editing the poem, with no change to the malware. Black Lotus Labs says the address is invisible outside the victim's own network traffic, and many control servers never appeared on crowd-sourced security tools. Teams can list which AI services, such as Ollama or LiteLLM, face the internet, watch their outbound connections, and ask who owns patching.