
Oct 8, 2026 · 7 min
Poe botnet hides command infrastructure in a GitHub poem
Poetry-powered botnet, Flock hits a roadblock, Outlook blocks risky installers
The episode shows how attackers can disguise botnet control infrastructure in an ordinary developer platform while compromising thousands of servers.
- 1Lumen’s Black Lotus Labs found Poe LLM malware on more than 3,400 servers since April.
- 2The botnet hides its command-and-control address inside a poem hosted on GitHub.
- 3Editing the poem lets attackers redirect the malware to new servers without changing the payload.
Don't miss
The report reveals that editing a GitHub-hosted poem can redirect the botnet’s compromised servers.
The brief
Sarah Lane reports on Lumen’s discovery of Poe LLM, malware that has compromised more than 3,400 servers since April and targets several exposed services.
The botnet’s unusual trick is operational rather than poetic: it stores its command-and-control address in a poem hosted on GitHub.
Because attackers can change the poem, they can redirect infected servers by editing a familiar developer platform instead of modifying the malware itself.
The episode closes by directing listeners to CISO Series for the full stories and weekday coverage of cybersecurity headlines.
Books & mentions
CISO Series
The episode points there for the full cybersecurity stories behind these headlines.