Create

Sign in to ReadmeX

or

How we handle your data: Privacy Policy

ReadmeX
ReadmeX

A clearer picture, in a conversation.

Catch up on what matters, then ask a little deeper.

Your community and people briefings stay personal to you.

Story

PoeLLM malware hides C2 addresses in GitHub poems, breaches 3,400+ servers

AI summary

Black Lotus Labs, the security research team under US telecom provider Lumen, disclosed the PoeLLM malware campaign, which has targeted internet-exposed AI and open-source services since at least April and compromised more than 3,400 servers. The infected machines are used for cryptocurrency mining and also scan and attack other systems. The malware retrieves its command-and-control (C2) server addresses from English poems stored in GitHub repositories, so attackers can simply edit keywords in a poem to point victims at a new C2 server.

Why it matters: The campaign shows that internet-facing AI and open-source services have become a prime attack surface for automated malware, and highlights an evasion trick that turns a public code repository into a C2 channel.

PoeLLMBlack Lotus LabsLumen

8
Source textiThome 台湾 · 1 min read

美國電信業者Lumen旗下資安研究團隊Black Lotus Labs揭露PoeLLM惡意程式攻擊行動,至少從今年4月起鎖定對外開放的AI及開源服務,累計入侵超過3,400臺伺服器。遭入侵的主機被用於加密貨幣挖礦,也會掃描及攻擊其他系統。

PoeLLM還利用存放在GitHub儲存庫中的英文詩取得指揮與控制(C2)伺服器位址,駭客只要修改詩中的關鍵字,就能讓受害主機連上新的控制伺服器。

受害主機主要分布在美國與西歐,不少運行LiteLLM、Ollama等AI服務,另有PDF轉換工具Gotenberg及軟體開發平臺Gitea。攻擊者會先掃描暴露在網際網路上的服務,再利用安全漏洞,要求目標伺服器從C2下載惡意程式,部分遭入侵的主機隨後被當成攻擊跳板,繼續搜尋及入侵其他伺服器,擴大殭屍網路規模。

PoeLLM的特殊之處,在於利用一首存放在GitHub儲存庫中的英文詩取得C2位址,駭客將該英文詩藏在名為dash.css的檔案中,惡意程式會讀取詩中4個指定位置的字詞,透過程式內建的對照表轉換成4個數字,再組合成C2伺服器的IP位址。當駭客更換控制伺服器,只要修改英文詩中的關鍵字,受害主機就能計算出新的連線位址,不必重新散布惡意程式。自4月13日首次上傳以來,該英文詩已修改11次。

針對LiteLLM,研究團隊在惡意程式樣本中發現與命令注入漏洞CVE-2026-42271相關的測試端點,推測可能是攻擊者利用的入侵途徑。部分C2位址指向管理介面有漏洞的路由器,研究團隊推測駭客可能利用遭入侵的路由器提供惡意程式下載及維持控制。截至報告發布時,研究團隊共辨識出12個C2位址,其中3個仍在活動。

Black Lotus Labs表示,已封鎖Lumen網路與已知PoeLLM C2伺服器間的通訊,並公布攻擊指標供企業檢查。研究團隊建議管理員檢查AI及開源服務是否直接暴露於網際網路、限制不必要的外部存取,並定期更新軟體及檢查網路紀錄,確認是否存在可疑通訊。

Read the original →

How we got here

  1. Terence Tao warns OpenAI's bulk AI math proofs cause 'proof indigestion'AIbase AI新闻 · GitHub
  2. OpenAI posts 719 AI-generated math proofs; three retracted for a sign error36氪 人工智能 · GitHub
  3. Developer uses Claude Opus 5.5 to clone seven Adobe apps as open source虎嗅 AI · GitHub
  4. Terence Tao faults OpenAI's 719 AI math proofs for 'proof indigestion'IT之家 AI · GitHub
  5. Jev: TypeSafe AI's probability-only model, explainedUnderstanding AI · GitHub
  6. hackingtool: AI-guided all-in-one security testing toolkit trends on GitHubGitHub Trending · Python · GitHub

Comments

I've used this: share my experience What I think: share my view
How important is this story?No ratings yet

No comments yet. Start the conversation.