Executive Summary
Since April 2024, the PoeLLM malware has compromised over 3,400 servers by exploiting AI services and using an innovative command-and-control mechanism hidden within a poem posted on GitHub. The threat actor, believed to be Italian-speaking, uses four specific words from the poem that map to IP addresses through a hard-coded dictionary, allowing dynamic C2 infrastructure changes without updating the malware itself. This botnet primarily focuses on cryptocurrency mining and exploit scanning while creating a network of AI-enabled proxies for potential downstream attacks. The technique demonstrates how threat actors are adapting to exploit the growing AI infrastructure landscape while using creative obfuscation methods to evade detection. The GitHub poem approach represents a new evolution in C2 resilience, as the infrastructure remains invisible to network monitoring tools unless the malware code is directly analyzed, highlighting the increasing sophistication of botnet operators.
Why This Matters Now
AI infrastructure attacks are surging as organizations rapidly adopt AI services without proper security controls, while this novel GitHub-based C2 technique could be replicated by other threat actors targeting cloud environments.
Attack Path Analysis
PoeLLM malware exploited vulnerabilities in AI services like LiteLLM, Ollama, and Ivanti Sentry to establish initial compromise. The malware escalated privileges through remote code execution capabilities, then spread laterally by converting compromised servers into attackers. Command and control operations used a novel poem-based obfuscation technique on GitHub to dynamically generate C2 addresses. The botnet exfiltrated credentials and tokens while mining cryptocurrency. The impact created a persistent army of AI-enabled proxies for ongoing attacks across 3,400+ compromised servers.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors exploited vulnerabilities in AI services including LiteLLM, Ollama, Gotenberg, Gitea, and Ivanti Sentry maximum-severity CVE to gain initial access to cloud servers hosting AI workloads
Related CVEs
CVE-2024-21893
CVSS 8.2A server-side request forgery vulnerability in Ivanti Connect Secure and Ivanti Policy Secure allows an authenticated attacker to send arbitrary requests from the appliance.
Affected Products:
Ivanti Connect Secure – < 9.1R14.4, < 9.1R17.2, < 9.1R18.3, < 22.4R2.2, < 22.5R1.1
Ivanti Policy Secure – < 9.1R17.2, < 9.1R18.3, < 22.5R1.1
Exploit Status:
exploited in the wildCVE-2024-21887
CVSS 9.1A command injection vulnerability in web components of Ivanti Connect Secure and Ivanti Policy Secure allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Affected Products:
Ivanti Connect Secure – < 9.1R14.4, < 9.1R17.2, < 9.1R18.3, < 22.4R2.2, < 22.5R1.1
Ivanti Policy Secure – < 9.1R17.2, < 9.1R18.3, < 22.5R1.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter: Unix Shell
Application Layer Protocol: Web Protocols
Obfuscated Files or Information: Command Obfuscation
Web Service: Dead Drop Resolver
Resource Hijacking
Proxy
Acquire Infrastructure: Domains
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – External Vulnerability Scanning
Control ID: 11.4.2
NYDFS 23 NYCRR 500.15 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15(a)
DORA ICT Risk Management Framework – Third-party Risk Management
Control ID: Article 8
CISA Zero Trust Maturity Model 2.0 – Network Traffic Analysis and Monitoring
Control ID: Networks - Advanced
NIS2 Directive – Incident Response and Business Continuity
Control ID: Article 21(2)(e)
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
AI services and open-source platforms face direct targeting by PoeLLM botnet, enabling cryptomining, lateral movement, and potential AI model abuse through compromised servers.
Computer Software/Engineering
GitHub-hosted repositories and development tools vulnerable to obfuscated C2 communications, with compromised LiteLLM, Ollama services enabling remote code execution capabilities.
Health Care / Life Sciences
HIPAA compliance at risk through encrypted traffic vulnerabilities and east-west lateral movement, particularly affecting AI-enabled medical systems and data protection controls.
Banking/Mortgage
Financial institutions face zero trust segmentation failures and egress security breaches, with botnet's cryptomining capabilities threatening PCI compliance and transaction integrity.
Sources
- PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poemhttps://cyberscoop.com/poellm-malware-botnet-poem-lumen-black-lotus-labs/Verified
- Black Lotus Labs PoeLLM Botnet Analysis Reporthttps://blog.lumen.com/poellm-botnet-uses-poem-for-c2-obfuscation/Verified
- CISA Alert on Ivanti Connect Secure Vulnerabilitieshttps://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060aVerified
- Ivanti Security Advisory for CVE-2024-21893 and CVE-2024-21887https://forums.ivanti.com/s/article/KB-Multiple-CVEs-for-Ivanti-Connect-Secure-and-Ivanti-Policy-SecureVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the scope of this AI service botnet attack through workload segmentation and east-west traffic enforcement. The segmented architecture could constrain lateral movement between compromised AI servers and limit the blast radius of the 3,400+ server compromise.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF visibility and monitoring could have provided earlier detection of exploitation attempts against AI services, though it would not have prevented the initial compromise through vulnerable applications
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation may have limited the scope of privilege escalation by restricting process execution paths and constraining access to system resources beyond the initially compromised AI service boundaries
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement could significantly constrain lateral movement between compromised AI servers, reducing the attack's ability to spread across the 3,400+ server infrastructure through network segmentation boundaries
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility may have detected the unusual GitHub-based C2 communication patterns and dynamic IP generation, though the novel obfuscation technique could potentially evade signature-based detection initially
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement could limit unauthorized data exfiltration attempts by restricting outbound traffic flows and constraining the botnet's ability to establish external communication channels for credential and token extraction
The cryptocurrency mining impact would likely be contained to isolated network segments rather than spanning the full 3,400+ server infrastructure, reducing computational resource abuse and business disruption
Impact at a Glance
Affected Business Functions
- AI/ML Model Operations
- Cryptocurrency Mining Infrastructure
- Open Source Development Services
- Secure Gateway Services
Estimated downtime: 7 days
Estimated loss: $150,000
Compromised AI model credentials, authentication tokens for LiteLLM and Ollama services, server access credentials, and potential exposure of AI training data and models across 3,400+ compromised servers. The botnet enables ongoing credential theft and token abuse through the private army of AI-enabled proxies.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate AI workloads and prevent lateral movement between compromised services using identity-based microsegmentation policies
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections and detect anomalous C2 communications through FQDN filtering and traffic analysis
- • Enable Multicloud Visibility & Control to monitor suspicious automation patterns and detect repeated malformed requests across AI service endpoints
- • Utilize Threat Detection & Anomaly Response capabilities to baseline normal AI service behavior and alert on covert tool deployment or unusual remote access patterns
- • Establish Cloud Native Security Fabric (CNSF) controls for real-time inspection and autonomous threat response to address AI-specific attack vectors and shadow AI risks



