Skip to main content
CyberReportedMediumDeveloping
5.4

PoeLLM botnet compromises 3,400+ servers, hides C2 in poem

A newly identified malware dubbed PoeLLM has infected over 3,400 servers, using a poem to conceal its command-and-control infrastructure coordinates. The technique is novel, but the scale is moderate; attribution and full impact remain unclear. This signals an evolving evasion tactic in server-side malware.

CyberScoop1 day agoengCredibility 37%View source

Score Breakdown

Mosaic Score5.4
Model confidence0.5
Significance0.5
Source credibility0.4
Source

Related signals

8 found