In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years
Description
This report summarizes multiple cybersecurity incidents and emerging threats including AI-assisted bank breaches in South Korea, a poem-guided botnet called PoeLLM targeting AI and open-source services, a supply chain attack on the Tensorlake npm SDK, and the sentencing of the Empire Market co-founder. The PoeLLM malware uses a novel method of hiding its command-and-control server IP address encoded in a GitHub-hosted poem. The Tensorlake npm SDK was compromised to deliver a credential-stealing worm. Nvidia's DCGM Exporter had a high-severity denial-of-service vulnerability that has been patched. The South Korean bank breaches are under investigation with AI suspected to be involved. The Empire Market co-founder received a 40-year prison sentence for running a dark web marketplace. These events highlight evolving attack techniques and ongoing law enforcement actions.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The PoeLLM malware, active since at least April 2026, targets exposed AI and open-source services such as LiteLLM, Ollama, Gotenberg, and Gitea to mine cryptocurrency and expand its botnet. It uniquely encodes its command-and-control server IP address using four keywords extracted from a poem hosted on GitHub, allowing dynamic server switching. The operator is assessed to be Italian-speaking. The Tensorlake npm SDK version 0.5.144 was compromised in a supply chain attack delivering a credential-stealing worm that harvests credentials from npm, GitHub, AWS, Kubernetes, Vault, and AI coding tools. Nvidia's DCGM Exporter had a denial-of-service vulnerability (CVE-2026-47483) allowing unauthenticated attackers to exhaust resources and crash the service; this has been patched in version 4.8.2. South Korean authorities are investigating recent bank breaches where AI tools were reportedly used, with CrowdStrike attributing the attacks with moderate confidence to a Chinese-speaking financially motivated threat actor. Raheim Hamilton, co-founder of the Empire Market dark web marketplace, was sentenced to 40 years in prison for drug conspiracy and related charges.
Potential Impact
The PoeLLM botnet can compromise AI and open-source service infrastructure to mine cryptocurrency and expand its network, potentially degrading service availability and security. The Tensorlake npm SDK compromise risks widespread credential theft across multiple cloud and development platforms, enabling further attacks. Nvidia's DCGM Exporter vulnerability could disrupt GPU monitoring and AI workloads, impacting performance and reliability. The South Korean bank breaches resulted in customer personal information exposure, with AI tools suspected to have facilitated the attacks, raising concerns about AI-assisted cybercrime. The Empire Market sentencing disrupts a major dark web marketplace involved in drug trafficking, stolen credentials, counterfeit currency, and hacking tools sales.
Defensive Guidance
Nvidia users should update the DCGM Exporter to version 4.8.2 or later to address the denial-of-service vulnerability. Users of the Tensorlake npm SDK should audit and update to a clean, uncompromised version and review credentials potentially exposed by the supply chain attack. Organizations running AI and open-source services targeted by PoeLLM should monitor for unusual mining activity and consider network segmentation and access controls. South Korean banks and other financial institutions should follow guidance from their authorities regarding the ongoing investigation and enhance monitoring for AI-assisted attack techniques. Law enforcement actions against dark web marketplaces like Empire Market continue to disrupt illicit activities.
Technical Details
- Classification
- {"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/in-other-news-ai-used-in-korean-bank-breaches-poem-guided-botnet-empire-admin-gets-40-years/","fetched":true,"fetchedAt":"2026-10-09T12:18:24.400Z","wordCount":1637}
Threat ID: 6ac8db912cdf04f656538359
Added to database: 10/09/2026, 12:18:25 UTC
Last enriched: 10/09/2026, 12:18:33 UTC
Last updated: 10/09/2026, 12:18:33 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.