A cryptomining botnet now takes its orders from a poem.
Researchers at Lumen's Black Lotus Labs found malware, dubbed PoeLLM, that scans the internet for exposed AI infrastructure like LiteLLM and Ollama installs, then pulls up a GitHub-hosted poem called "On the Nature of Connection" to find its command server. The malware checks the poem for four words - driver, diode, encryption, tick - runs them through a hardcoded dictionary, and converts the result into an IPv4 address. That address is the botnet's command-and-control server, which typically tells infected machines to run the XMRig Monero miner or scan for more vulnerable targets. The poem has been edited 11 times since it first appeared, most recently in September 2026, and each edit silently relocates the C2 server for every infected machine that reads it. Black Lotus Labs says the operator appears to be based in Italy and has already compromised more than 3,000 devices.
What makes this campaign notable isn't the poem gimmick - it's the targeting breadth. Where the LiteLLM supply-chain compromise earlier this year hit roughly 2,500 victims through a single flaw, PoeLLM hunts across multiple AI-related services at once, which keeps its victim pool from drying up the way single-exploit botnets usually do. Encoding the C2 address in editable text also means the attacker can move infrastructure instantly, without pushing a malware update or worrying about static IP blocklists.
Security teams have flagged AI-generated phishing and deepfakes for years; apparently AI-generated verse can also double as a change-of-address form for a botnet.