Skip to main content

In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years

0
High
Published: 10/09/2026 (10/09/2026, 12:03:50 UTC)
Source: SecurityWeek

Description

This report summarizes multiple cybersecurity incidents and emerging threats including AI-assisted bank breaches in South Korea, a poem-guided botnet called PoeLLM targeting AI and open-source services, a supply chain attack on the Tensorlake npm SDK, and the sentencing of the Empire Market co-founder. The PoeLLM malware uses a novel method of hiding its command-and-control server IP address encoded in a GitHub-hosted poem. The Tensorlake npm SDK was compromised to deliver a credential-stealing worm. Nvidia's DCGM Exporter had a high-severity denial-of-service vulnerability that has been patched. The South Korean bank breaches are under investigation with AI suspected to be involved. The Empire Market co-founder received a 40-year prison sentence for running a dark web marketplace. These events highlight evolving attack techniques and ongoing law enforcement actions.

Affected software

Affected versions
=0.5.144<4.8.2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 12:18:33 UTC

Technical Analysis

The PoeLLM malware, active since at least April 2026, targets exposed AI and open-source services such as LiteLLM, Ollama, Gotenberg, and Gitea to mine cryptocurrency and expand its botnet. It uniquely encodes its command-and-control server IP address using four keywords extracted from a poem hosted on GitHub, allowing dynamic server switching. The operator is assessed to be Italian-speaking. The Tensorlake npm SDK version 0.5.144 was compromised in a supply chain attack delivering a credential-stealing worm that harvests credentials from npm, GitHub, AWS, Kubernetes, Vault, and AI coding tools. Nvidia's DCGM Exporter had a denial-of-service vulnerability (CVE-2026-47483) allowing unauthenticated attackers to exhaust resources and crash the service; this has been patched in version 4.8.2. South Korean authorities are investigating recent bank breaches where AI tools were reportedly used, with CrowdStrike attributing the attacks with moderate confidence to a Chinese-speaking financially motivated threat actor. Raheim Hamilton, co-founder of the Empire Market dark web marketplace, was sentenced to 40 years in prison for drug conspiracy and related charges.

Potential Impact

The PoeLLM botnet can compromise AI and open-source service infrastructure to mine cryptocurrency and expand its network, potentially degrading service availability and security. The Tensorlake npm SDK compromise risks widespread credential theft across multiple cloud and development platforms, enabling further attacks. Nvidia's DCGM Exporter vulnerability could disrupt GPU monitoring and AI workloads, impacting performance and reliability. The South Korean bank breaches resulted in customer personal information exposure, with AI tools suspected to have facilitated the attacks, raising concerns about AI-assisted cybercrime. The Empire Market sentencing disrupts a major dark web marketplace involved in drug trafficking, stolen credentials, counterfeit currency, and hacking tools sales.

Defensive Guidance

Nvidia users should update the DCGM Exporter to version 4.8.2 or later to address the denial-of-service vulnerability. Users of the Tensorlake npm SDK should audit and update to a clean, uncompromised version and review credentials potentially exposed by the supply chain attack. Organizations running AI and open-source services targeted by PoeLLM should monitor for unusual mining activity and consider network segmentation and access controls. South Korean banks and other financial institutions should follow guidance from their authorities regarding the ongoing investigation and enhance monitoring for AI-assisted attack techniques. Law enforcement actions against dark web marketplaces like Empire Market continue to disrupt illicit activities.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/in-other-news-ai-used-in-korean-bank-breaches-poem-guided-botnet-empire-admin-gets-40-years/","fetched":true,"fetchedAt":"2026-10-09T12:18:24.400Z","wordCount":1637}

Threat ID: 6ac8db912cdf04f656538359

Added to database: 10/09/2026, 12:18:25 UTC

Last enriched: 10/09/2026, 12:18:33 UTC

Last updated: 10/09/2026, 12:18:33 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses