// 4 ZERO-DAY · 6 CVE · 9 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
Three developments define the week in threat intelligence: the PoeLLM botnet reconstructs its command-and-control IP from keywords hidden in a poem hosted on GitHub; South Korean authorities and CrowdStrike confirm AI tools were used offensively in recent bank intrusions; and a U.S. court sentences Empire Market co-founder Raheim Hamilton to 40 years in prison.

On October 9, 2026, SecurityWeek published its regular "In Other News" roundup covering three episodes that illustrate the evolving threat landscape. The PoeLLM malware leverages a poem hosted on GitHub to dynamically reconstruct its command-and-control server address. South Korea discloses bank breaches in which artificial intelligence appears as an offensive component, not a target. In the United States, a court sentences Raheim Hamilton, co-founder of the Empire Market darknet marketplace, to 40 years in prison. The week reveals a convergence: trusted platforms, legitimate AI tools, and established criminal infrastructure are overlapping in novel ways.

Key Takeaways
  • PoeLLM, active since at least April 2026, extracts four keywords from a GitHub-hosted poem to generate its C2 server IP; the operator can relocate infrastructure simply by changing words in the text.
  • South Korean President Lee Jae Myung stated there are "signs that AI was used" in recent attacks on the country's banks; CrowdStrike found Claude Code session history and ARTEX files in the attack infrastructure.
  • CrowdStrike attributes the bank attacks to a financially motivated Chinese threat actor with moderate confidence.
  • Raheim Hamilton, 30, of Virginia, received a 40-year prison sentence and a $5 million fine after pleading guilty to drug conspiracy tied to Empire Market, which operated from 2018 to 2020.

The Poem as a Resilience Mechanism: How PoeLLM Works

Black Lotus Labs documented the core mechanism of PoeLLM with technical precision. The malware, active since at least April 2026, targets exposed AI and open-source services — primarily LiteLLM, Ollama, Gotenberg, and Gitea. Once a machine is compromised, the botnet retrieves a poem hosted on GitHub and extracts four specific keywords. Those words are converted into an IP address pointing to the current C2 server.

The operator — assessed by Black Lotus Labs as Italian-speaking — has updated the poem 11 times. Each textual change potentially shifts the command infrastructure to a new address without requiring new malware samples or code modifications on already-compromised hosts. The mechanism replaces classic techniques such as domain generation algorithms (DGAs) or hardcoded DNS with an alternative resolution method that exploits GitHub's trust reputation.

This architectural choice yields clear operational advantages for the attacker. Requests to GitHub do not trigger alerts in network security systems: the domain is legitimate, the content is innocuous text, and the traffic blends with millions of daily developer interactions. C2 persistence depends on the ability to modify a public file, not on managing dedicated, costly infrastructure.

Precedents and Context: From Pastebin to Collaborative Platforms

The editorial briefing draws a comparison with historical techniques: Twitter as a C2 channel, Pastebin for payload hosting. PoeLLM represents an iteration that leverages the maturity of modern collaborative platforms. GitHub offers high availability, accessible APIs, built-in versioning, and a low-risk profile for perimeter defenses. The poetic steganography is not a literary curiosity but a signal of evolution in criminal infrastructure engineering.

The dossier does not specify whether GitHub has detection tools for similar patterns. This gap is relevant: the platform is not designed for semantic analysis of textual content hunting for hidden channels, and the problem of proactive moderation of steganographic patterns remains open.

AI as an Offensive Component in South Korean Bank Breaches

On October 9, 2026, South Korean President Lee Jae Myung declared that recent hacking against the country's banks showed "signs that AI was used." South Korean police have launched a full-scale investigation: the attacks caused breaches of customer personal information, but the full scope — number of institutions involved, records exposed, financial impact — is not specified in available sources.

CrowdStrike supplied technical evidence supporting the hypothesis of AI used as a tool, not a target. The threat intelligence firm found Claude Code session history, ARTEX configuration files, and Claude memory files during analysis of the attack infrastructure. These artifacts indicate legitimate AI tools were employed as components of the offensive ecosystem, not that the banks were breached through vulnerabilities specific to AI models or services.

Attribution remains cautious. CrowdStrike assesses with moderate confidence that a financially motivated Chinese threat actor is behind the attacks. The dossier reveals no infrastructure overlaps linking this actor to previously known clusters, nor is it clear whether this is a new group or an evolution of documented capabilities.

"CrowdStrike this week reported finding Claude Code session histories, ARTEX configuration files, and Claude memory files while analyzing the attack infrastructure"

Paradigm Shift: When AI Stops Being Just a Target

A technical reading of the South Korean facts requires separating two concepts often conflated. AI security has so far focused resources on protecting models: adversarial attacks, data poisoning, jailbreaks, weight exfiltration. The attacks documented by CrowdStrike show AI used as an operational accelerator for a human actor: Claude Code as a tool for interacting with infrastructure, not as an autonomous compromise vector.

The implications for threat modeling frameworks are concrete. Defenses must account for legitimate AI tools, accessible with standard credentials or enterprise configurations, appearing in attack chains as post-compromise elements. Detection of unauthorized Claude Code sessions becomes an indicator of compromise, not a usage anomaly. The dossier does not specify what controls the targeted banks had implemented, nor whether Claude Code was used on the attacker's compromised systems or on victim assets.

Empire Market: Hamilton's Sentencing and Dark Market Jurisprudence

Raheim Hamilton, 30, of Virginia, was sentenced on October 9, 2026, to 40 years in prison and a $5 million fine. Hamilton pleaded guilty to drug conspiracy related to Empire Market, a dark web platform that processed over four million transactions worth more than $430 million between 2018 and 2020.

Empire Market's criminal profile was composite. The majority of transactions involved drug sales, but the platform also hosted stolen credentials, personal information, counterfeit currency, and hacking tools. Hamilton ran the site with Thomas Pavey, who pleaded guilty the previous year and is scheduled to be sentenced by the end of the current month. The dossier does not specify whether Pavey will receive a comparable sentence.

Empire Market represents the centralized darknet marketplace model, now partly supplanted by decentralized alternatives but still relevant for jurisprudence. Hamilton's conviction confirms the continued effectiveness of judicial action against long-running criminal infrastructure, even years after the platform went offline. The signal to operators is direct: the latency between criminal activity and legal consequences can be long, but the severity of penalties is increasing.

Why It Matters

The dossier presents limitations that should be explicit. The exact number of hosts compromised by PoeLLM is not documented, nor is it clear whether the 11 poem modifications correspond to 11 C2 server changes or include other updates. The source does not specify the nature of personal data exposed in the South Korean bank breaches or the initial access mechanism. On the Empire Market front, the brief does not document specific remedial measures or seizure protocols used by U.S. authorities.

What the dossier does document, however, is sufficient to trace three evolutionary vectors. PoeLLM demonstrates that "lightweight" steganography on trusted platforms is operationally viable and difficult to intercept with conventional tools. The South Korean breaches show AI migrating from the category of protected targets to that of offensive tools, with consequences not yet reflected in defense frameworks. Hamilton's conviction confirms that judicial action retains deterrent effect against established criminal infrastructure. The week presents no zero-day vulnerabilities to patch, but strategic patterns to monitor.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. securityweek.com
  2. radar.offseq.com
  3. news4hackers.com
  4. itsecuritynews.info
  5. github.com