Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers #malware

Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers #malware
MATCHBOIL: New tricks, same old evil intentions #malware
New budget Android phones are arriving with firmware malware installed before you even turn them on.
PoeLLM malware has compromised 3,400+ servers, mainly by targeting exposed AI and open-source services.
It finds its current C2 server by decoding four words from a poem hosted on GitHub.
DOJ Seizes Seven Domains Used for Alleged China-Linked Hacking of Critical Infrastructure
blog.talosintelligence.com/ignore-all-i... Excellent research post from CISCO Talos team discussing Anti AI analysis techniques in malware.
Someone searches for a tool, clicks the advert above the real result, and lands on a copy of the brand. Researchers see a blank page; victims see the fake. The fix costs nothing: install from the vendor's site, typed in directly. Read the filing #malware #malvertising #browser #infosec
#PoeLLM #malware infects exposed #AI servers in #cryptomining attacks
Stealthy ASHVEIN RAT hides commands in HTML to spy on Ukrainian gov, infrastructure. #Cybersecurity #Russia #Ukraine #RAT #Espionage #Malware https://thedailytechfeed.com/uac-0099s-new-rat-ashvein-spies-on-ukraine-via-hidden-html-commands/
⚠️📢 Some low-cost Android phones may arrive compromised before users even switch them on.
#MidnightMimosa malware is preinstalled in system firmware, enabling ad fraud, proxyware and silent app installation.
Listen/Read: hackread.com/midnight-mim...
📢 Un malware retrouve son serveur de commande dans un poème et compromet plus de 3’400 serveurs
Un malware baptisé PoeLLM exploite des serveurs vulnérables, notamment ceux hébergeant des outils d'IA comme LiteLLM et Ollama.
Fake hotel reviews are being used as phishing lures to install EtherRAT/TONResolver malware with blockchain C2 hiding. #Blockchain #EtherRAT #TONResolver #Phishing #Malware https://thedailytechfeed.com/hotel-staff-targeted-malware-uses-negative-reviews-to-hide-c2-in-blockchain/
Malware is now querying smart contracts to hide C2 domains—supply chain security risks just got smarter with Web3. #Web3 #SupplyChainSecurity #BlockchainC2 #Malware #CloudSecurity https://thedailytechfeed.com/hackers-turn-public-blockchains-into-stealth-c2-hubs-in-supply-chain-attacks/
☠️ Ingeniería Inversa del Fraude: Así es como #MagisTV (ahora #Xuper) inyecta #malware, secuestra tu red y roba tus datos bancarios 📱 | #Streaming
Análisis técnico de overlays botnets y robo de #datos bancarios.
Virus preinstallato sugli smartphone Android economici: allarme #Android #cubot #doogee #firmware #francia #google #iphone #iphoneduo #italia #mac #malware #meta #sicurezza #smartphone #spagna #statiuniti #truffa 🔗 https://guruhitech.com/virus-preinstallato-smartphone-android-economici-midnight...
@talosintelligence.com
Attackers embed prompt injections to manipulate AI malware analysis; plaintext enables detection.
-
IOCs: CVE-2015-2291, F8f5e0440c57c7deffd75ca33e2511867039796aa803e7ef847396a379188a7d
-
#AI #Malware #ThreatIntel
~Malpedia~
Open-source XenoRAT enables C2, HVNC, surveillance, credential theft and remote control.
-
IOCs: 201[.]7[.]16[.]168:5555
-
#Malware #RAT #ThreatIntel
16 Firefox extensions posing as Rabby/OKX wallet clones stole recovery phrases. All removed—reset your wallet if compromised. #Security #BrowserSecurity #Crypto #Malware #Firefox https://thedailytechfeed.com/16-firefox-wallet-extensions-stole-crypto-recovery-phrases-all-removed/