The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

Since April 2024, the PoeLLM malware has compromised over 3,400 servers by exploiting AI services and using an innovative command-and-control mechanism hidden within a poem posted on GitHub. The threat actor, believed to be Italian-speaking, uses four specific words from the poem that map to IP addresses through a hard-coded dictionary, allowing dynamic C2 infrastructure changes without updating the malware itself. This botnet primarily focuses on cryptocurrency mining and exploit scanning while creating a network of AI-enabled proxies for potential downstream attacks. The technique demonstrates how threat actors are adapting to exploit the growing AI infrastructure landscape while using creative obfuscation methods to evade detection. The GitHub poem approach represents a new evolution in C2 resilience, as the infrastructure remains invisible to network monitoring tools unless the malware code is directly analyzed, highlighting the increasing sophistication of botnet operators.

Why This Matters Now

AI infrastructure attacks are surging as organizations rapidly adopt AI services without proper security controls, while this novel GitHub-based C2 technique could be replicated by other threat actors targeting cloud environments.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The malware extracts four specific words from a GitHub-hosted poem and maps them through a hard-coded dictionary to IP addresses, allowing dynamic C2 changes without malware updates.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the scope of this AI service botnet attack through workload segmentation and east-west traffic enforcement. The segmented architecture could constrain lateral movement between compromised AI servers and limit the blast radius of the 3,400+ server compromise.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF visibility and monitoring could have provided earlier detection of exploitation attempts against AI services, though it would not have prevented the initial compromise through vulnerable applications

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation may have limited the scope of privilege escalation by restricting process execution paths and constraining access to system resources beyond the initially compromised AI service boundaries

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement could significantly constrain lateral movement between compromised AI servers, reducing the attack's ability to spread across the 3,400+ server infrastructure through network segmentation boundaries

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility may have detected the unusual GitHub-based C2 communication patterns and dynamic IP generation, though the novel obfuscation technique could potentially evade signature-based detection initially

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress policy enforcement could limit unauthorized data exfiltration attempts by restricting outbound traffic flows and constraining the botnet's ability to establish external communication channels for credential and token extraction

Impact (Mitigations)

The cryptocurrency mining impact would likely be contained to isolated network segments rather than spanning the full 3,400+ server infrastructure, reducing computational resource abuse and business disruption

Impact at a Glance

Affected Business Functions

  • AI/ML Model Operations
  • Cryptocurrency Mining Infrastructure
  • Open Source Development Services
  • Secure Gateway Services
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $150,000

Data Exposure

Compromised AI model credentials, authentication tokens for LiteLLM and Ollama services, server access credentials, and potential exposure of AI training data and models across 3,400+ compromised servers. The botnet enables ongoing credential theft and token abuse through the private army of AI-enabled proxies.

Recommended Actions

  • • Implement Zero Trust Segmentation to isolate AI workloads and prevent lateral movement between compromised services using identity-based microsegmentation policies
  • • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections and detect anomalous C2 communications through FQDN filtering and traffic analysis
  • • Enable Multicloud Visibility & Control to monitor suspicious automation patterns and detect repeated malformed requests across AI service endpoints
  • • Utilize Threat Detection & Anomaly Response capabilities to baseline normal AI service behavior and alert on covert tool deployment or unusual remote access patterns
  • • Establish Cloud Native Security Fabric (CNSF) controls for real-time inspection and autonomous threat response to address AI-specific attack vectors and shadow AI risks

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image