PoeLLM Cryptomining Botnet Hides C2 in Poem, Infects Thousands of Servers
A botnet, identified as PoeLLM by some reports, has infected thousands of servers by using a novel technique to hide its command and control (C2) addresses within a poem hosted on GitHub. While some outlets describe it as a general AI security threat, one report specifies its primary activity as cryptomining. The number of affected servers is reported to be around 3,400.
3 articles from 3 outlets covered this story. Their coverage differs on 2 points. The underlying claim is sourced from a press release.
What do all outlets agree on?
3 outlets covered “PoeLLM Cryptomining Botnet Hides C2 in Poem, Infects Thousands of Servers”. All of them report the following:
- Malware/botnet infection
- Hides C2 addresses in a poem
- Poem used for C2 communication
- Infected thousands of servers
Did outlets disagree about this?
Yes. Coverage of “PoeLLM Cryptomining Botnet Hides C2 in Poem, Infects Thousands of Servers” differs on 2 points. Each account below is how a different outlet described the same event:
The malware is specifically named 'PoeLLM'.
The primary activity of the botnet is cryptomining.
Which figures do outlets report differently?
1 figure in this story is reported with conflicting values:
Which outlets covered this?
All 3 articles found on this story, grouped by the stance of the piece. Every link goes to the original publisher.