- Lumen's Black Lotus Labs says PoeLLM, malware that targets open-source AI services, has compromised more than 3,400 servers since April. It uses a GitHub poem to find its controller.
- The poem holds no link, file or code, so it gives defenders nothing obvious to block. The control address shows only in a victim's own network traffic.
- Review outbound network traffic from self-hosted AI and developer tools, and confirm someone owns each one.
The most useful instruction a piece of malware can receive is one that looks like nothing. A poem on GitHub fits that description. Lumen Technologies' Black Lotus Labs says a botnet it calls PoeLLM relies on exactly that.
In a report published Wednesday, Black Lotus Labs counted more than 3,400 compromised servers, with activity dating back to April. The malware goes after open-source AI services. The lesson for executives is that the weak point may not be the malware itself. It may be the AI tools your own teams installed and forgot.
How a poem becomes an address
Most malware needs to find its controller, known as a command-and-control or C2 server. Usually the address is written into the code, or points to a web page that holds it. Defenders hunt for those addresses and block them.
PoeLLM works differently. According to the report, the malware downloads a poem that the threat actor posted on GitHub. It then picks out four words by where they sit relative to fixed anchor text in the verse.
Each word is looked up in a dictionary built into the malware. Every word maps to a number. In one example from the researchers, "driver" equals 92 and "diode" equals 119. The four numbers together form the current C2 address.
The attacker can rewrite the poem and change the address without touching the malware. The researchers say the keywords have changed at least a dozen times.
Why this is hard to catch
Black Lotus Labs engineer Ryan English told CyberScoop that only the victim's own network traffic records reveal where the malware is calling. Anyone else who reads the verse sees a poem and nothing more.
Nothing in it can be clicked, downloaded or decoded. That leaves little for a scanner to flag. English said a researcher would have no reason to call the poem malicious without the malware that refers to it.
That matters because many security teams lean on shared threat feeds. English said many of the C2 servers in this campaign never appeared on crowd-sourced security tools. In his view, the poem layer helped keep them hidden.
The design also resists takedowns. English said the botnet turns compromised servers into attackers and shifts its C2 infrastructure. If one exploit server is reported, the attacker can route attacks through hundreds of other victims.
Why AI services are the target
Black Lotus Labs first met PoeLLM infrastructure in June. It was investigating a maximum-severity defect in Ivanti's Sentry secure mobile gateway. That led to an exploit-scanning and cryptocurrency-mining botnet tied to compromised services including LiteLLM, Ollama, Gotenberg and Gitea.
English said the malware can allow remote code execution. That could let an attacker abuse AI models on a victim's server, and use public-facing services to reach others. He described the result as "a private army of AI-enabled proxies."
Some limits apply. The researchers say the actor's goals beyond exploit scanning and mining are still under investigation. They do not know how many people run the operation. They have seen no links to other groups. They say the actor is likely Italian or Italian-speaking, based on code comments and Italy-based servers.
This is one campaign, not proof of a wider trend. It does show a risk that fits this publication's view: AI tools multiply exposure. A forgotten model server is a computer with credentials, compute and an internet connection.
What to ask your team
First, ask for a list of self-hosted AI and developer tools that face the internet. The report names LiteLLM, Ollama, Gotenberg and Gitea. Ask who owns each one and who patches it.
Second, ask where you would see this behavior. Because the address appears only in a victim's own traffic, your network flow records are the place to look. Ask whether anyone reviews outbound connections from these servers.
Third, check what an attacker would gain from each tool. Credentials, API tokens and model access all sit on these machines. Ask what is stored there and how quickly it could be rotated.
Blocklists tell you what others have already found. A poem whose keywords have changed at least a dozen times since April shows why you also need to watch your own servers.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CyberScoop.





