Black Lotus Labs
AI overview
Sign in and the AI will write an overview from our coverage.
Headlines · 1
- PoeLLM malware hides C2 addresses in GitHub poems, breaches 3,400+ servers
Black Lotus Labs, the security research team under US telecom provider Lumen, disclosed the PoeLLM malware campaign, which has targeted internet-exposed AI and open-source services since at least April and compromised more than 3,400 servers. The infected machines are used for cryptocurrency mining and also scan and attack other systems. The malware retrieves its command-and-control (C2) server addresses from English poems stored in GitHub repositories, so attackers can simply edit keywords in a poem to point victims at a new C2 server.
iThome 台湾 · 🔥 7
Experience and discussion from the community
Share my Black Lotus Labs experienceAsk about Black Lotus Labs
Nobody has shared their experience with Black Lotus Labs yet.