news.today
Hello · Register today | LoginHello · My Account[—] [31]
Tech

Malware uses poems on GitHub to infect thousands of servers

Summarised from 2 outlets · Updated 8 Oct, 17:37 · Archive

Attackers have infected over 3,000 servers using malware that decodes hidden messages from poems posted on GitHub.

Cybersecurity researchers from Lumen's Black Lotus Labs have discovered a new malware attack that uses poems posted on GitHub to instruct infected systems. The malware, called PoeLLM, has infected more than 3,000 servers. The attacker first targets vulnerable internet-facing services such as LiteLLM or Ollama and installs the malware.

Once installed, PoeLLM searches GitHub for a poem that appears to be AI-generated. The malware decodes specific words from the poem into numbers that form an IP address, revealing the location of the attacker's command-and-control server. From there it receives instructions on what to do next. Lumen's Black Lotus Labs calls this technique 'adversarial poetry' and states it has never encountered anything like it before.

The attacker appears to be of Italian origin or based in Italy, according to researchers. The method is unusual in using poetry as a delivery mechanism for malware instructions, bypassing traditional security detection methods.

Malware uses poems on GitHub to infect thousands of servers
Image: TechRadar

Comments (0)

How it is being reported

In this story: PoeLLM · Lumen's Black Lotus Labs · GitHub · Italy

This summary was written by AI from the headlines and standfirsts above, and states as fact only what at least two outlets report. How we use AI · Report a problem