VYPR
researchPublished Oct 7, 2026· 3 sources

PoeLLM Malware Leverages Poem for Resilient Botnet Infrastructure

A sophisticated malware campaign dubbed PoeLLM has compromised over 3,400 servers by ingeniously using a poem posted on GitHub as a dynamic lookup table to generate command-and-control server addresses.

A stealthy malware operation, identified as PoeLLM, has successfully compromised more than 3,400 servers since April, according to a report by Lumen Technologies' Black Lotus Labs. This campaign distinguishes itself through a novel technique where a poem, posted on a public GitHub repository, serves as the foundation for generating dynamic command-and-control (C2) server addresses. This method significantly enhances the malware's resilience and makes its infrastructure exceptionally difficult to track and disrupt.

The core of PoeLLM's evasion strategy lies in its use of specific words extracted from the poem. These words, which have been altered at least a dozen times, are processed through a hard-coded dictionary within the malware to construct the IP address for C2 communications. This approach allows threat actors to change their C2 infrastructure without needing to update the malware itself, a common vulnerability in many botnet operations. "The most interesting piece of the poem approach is that the IP address used for C2 communications is invisible outside of the victim’s netflow," explained Ryan English, information security engineer at Black Lotus Labs. "To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious."

Researchers first detected PoeLLM infrastructure in June while investigating a critical vulnerability affecting Ivanti's Sentry secure mobile gateway product. The investigation uncovered a widespread botnet engaged in exploit scanning and cryptocurrency mining, linked to various compromised services and tools, including LiteLLM, Ollama, Gotenberg, and Gitea. While PoeLLM has demonstrated significant success in compromising AI-related services at scale, the full extent of the threat actor's activities beyond these initial functions is still under investigation.

The malware possesses capabilities for remote code execution, which could enable threat actors to abuse AI models and public-facing services on victim servers for further exploitation. "Through the growth of this botnet, the actor has effectively created a private army of AI-enabled proxies, which will continue to multiply and provide additional vectors for attack, credential theft, token abuse and more," English stated. The botnet's ability to convert compromised servers into attack platforms and pivot through its C2 infrastructure leaves minimal traces, making it challenging for security researchers to pinpoint and dismantle.

For instance, the poem's structure provides a dynamic lookup mechanism. When PoeLLM retrieves an updated version of the poem from GitHub, it extracts four specific words based on their position relative to fixed text anchors. Each extracted word is then cross-referenced with the embedded dictionary, where individual words map to numerical values. These numbers are then combined to form the current C2 server address. This sophisticated obfuscation ensures that many of the C2 servers used in the campaign were never flagged by crowd-sourced security tools, significantly boosting the campaign's stealth.

An example provided by Black Lotus Labs illustrates this technique. In one observed version of the poem, specific words like "driver," "diode," "decryption," and "string" mapped to numerical values. When the threat actor modifies these keywords within the poem, the malware automatically calculates a new C2 address, rendering the infrastructure invisible to network monitoring tools unless the malware code itself is directly analyzed.

Based on linguistic analysis of comments within the malware code and the reliance on Italy-based servers for testing and C2 infrastructure, researchers at Black Lotus Labs believe the threat actor behind PoeLLM is likely Italian or speaks Italian. The exact number of individuals involved in the operation remains unknown, and no connections to other threat groups or campaigns have been identified thus far.

The PoeLLM campaign highlights a growing trend of threat actors leveraging unconventional methods to build resilient and evasive infrastructure. By embedding critical operational elements within seemingly innocuous public content like a poem, attackers can significantly complicate detection and response efforts, posing a persistent threat to organizations relying on open-source AI services.

The new article provides further technical details on the PoeLLM malware's command-and-control (C2) mechanism, explaining how it parses specific phrases from an 'adversarial poem' on GitHub to dynamically generate C2 server IP addresses. It also details the specific logic used to extract these phrases and convert them into numerical values, highlighting the sophistication of the attacker's evasion techniques. Additionally, the report attributes the malware to an Italian-speaking actor and names the campaign 'Canto Incognito'.

This new reporting from The Hacker News provides further details on the Canto Incognito campaign, specifically highlighting the malware's method of hiding its command-and-control (C2) server address within a poem hosted on GitHub. Researchers noted that the threat actors creatively alter words in the poem to dynamically update the C2 address, making it more resilient to takedowns. Additionally, the article specifies that the malware targets enterprise-facing deployments like LiteLLM, Gotenberg, Gitea, and Ivanti Sentry appliances, and attributes the activity with moderate confidence to an Italian-speaking threat actor.

Synthesized by Vypr AI