www.securityweek.com 9 Oct 2026, 12:03 UTC

Poem Guided Botnet Hijacks AI Services to Mine Cryptocurrency

Poem Guided Botnet Hijacks AI Services to Mine Cryptocurrency
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

SECURITYWEEK reports a string of cyber security items in this week’s “In Other News.” Notable among them are AI-enabled attacks against Korea’s banking sector, a poem-guided botnet operation, and long prison terms for high‑profile cybercrime figures.

In South Korea, authorities are investigating claims that AI assisted recent bank breaches and exposed customer data; CrowdStrike notes traces of Claude Code session histories and ARTEX configuration/memory files in related infrastructure, with a Chinese-speaking, financially motivated actor suspected but not yet confirmed. Precise tools or campaigns remain undisclosed by official sources.

On the operational side, researchers describe several concrete technical developments. PoeLLM malware, active since at least April 2026, uses a poem hosted on GitHub to encode the C2 server’s IP address, enabling the botnet to switch commanders by altering the four concealed keywords; the malware targets exposed AI/open-source services to mine cryptocurrency and expand its network.

Separately, Nvidia’s DCGM Exporter flaw, CVE-2026-47483, allows unauthenticated attackers to overwhelm profiling endpoints and crash the service;証据 from scans show about 2,100 hosts exposed to the internet, affecting more than 12,000 GPUs. Nvidia has issued fixes (version 4.8.2+). The piece also notes a Shai‑Hulud‑style supply chain compromise of Tensorlake’s npm SDK (version 0.5.144), enabling credential theft across npm, GitHub, AWS, Kubernetes and Vault.

The report highlights other high‑profile items, including the Empire Market sentencing and the GhostAction stealth campaign, but these are separate summaries with their own details.

View full article

Article by CyberSIXT