Tech News
← Home  ·  All topics

Poellm Malware

1 GoKawiil brief on this topic

PoeLLM malware uses GitHub poem to control cryptomining botnet on 3,400 AI servers

Black Lotus Labs reports that a malware strain called PoeLLM has compromised more than 3,400 exposed AI servers, with up to 800 infected systems active on a single day. The malware, an ELF file named libgcrypt, derives its command-and-control IP address by extracting keywords from a poem hosted in a GitHub repository, updating the poem 11 times since April to rotate C2 addresses.