Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet.
This is the first case of “adversarial poetry” - an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails - that Lumen’s Black Lotus Labs, which has been tracking the PoeLLM malware, has seen in real-world attacks.
“This is a first for us,” the researchers told The Register via email.
“While we can't get inside the threat actor's head, we think the attacker might have used a poem because it serves as a perfect vehicle for hiding an important message,” they added. “To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models. There would be no reason for any security researcher to identify this poem as malicious - or know about the IP address hidden within it - unless they had access to the malware referencing it.”
PoeLLM malware has been active since at least April, impacting more than 3,000 servers primarily located in the US and Western Europe, and it continues to infect new victims. At its peak, the malware infected more than 800 active servers per day.
The malware abuses - and scans for - open source AI systems and services. Most of the victims were running vulnerable, internet-facing versions of LiteLLM and Ollama. Additionally, hundreds of victims were running Gotenberg, a PDF converter, and software development platform Gitea.
In addition to these open source tools, the attacker may have targeted commercial software including Ivanti Sentry. The threat hunters first spotted the PoeLLM malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520.
“In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122,” according to a Wednesday report shared with The Register. “Shortly after contacting this C2, the Ivanti Sentry victim began scanning for other vulnerable devices.”
How adversarial poetry works
Black Lotus Labs attributed the PoeLLM malware to an Italian-speaking criminal, and named the financially motivated campaign Canto Incognito because it hides the malicious commands in a poem posted to a GitHub repository.
“Comments within the malware and on the attacker’s GitHub pages are in Italian, and netflow analyzed by Black Lotus Labs suggests that the attacker is located in Italy,” the threat-hunters told us, adding that they believe the campaign targets AI systems and that the poem itself was written by AI.
The malware deploys XMRig and Iron miners, and connects victims to Kryptex mining infrastructure.
In addition to using compromised GPU hardware powering AI workloads to mine cryptocurrency, PoeLLM also turns victims' machines into vulnerability scanners and exploit servers, which allows the attacker to compromise even more vulnerable systems.
The researchers’ investigation indicates that the cryptojacking miscreant - aka GitHub user “ejejejdfbbebe” - made the first GitHub commit with the adversarial poem on April 13. The repo is a fork of the nodejs.org website source code, and the file is called “dash.css.” Inside the file, there’s a poem titled “On the Nature of Connection,” which has been updated 11 times since its initial commit. Here’s the most current version, as of September:
In the silent hum of driver, the machines begin to speak,
Each pulse of diode threading light through copper veins.
we taught the dark to carry meaning, byte by byte —
A language built from lightning, cold and clean.
Beyond the wall of encryption, a signal finds its way,
the tick of distant servers answering back.
Data moves like water through the cracks of ordered thought,
and somewhere in the code, the world stays on track.
Here’s the adversarial piece: the malware finds its current command-and-control (C2) server from keywords in the poem, and when the operator changes the poem, the infected systems find the new C2 location. It does this by parsing the poem, extracting certain words and phrases, and then converting them to numbers using a hard-coded dictionary in the body of the malware.
Black Lotus Labs says the logic for C2 discovery works like this:
The function “extract_poem_phrase_field” extracts three words/phrases from the body of the poem, case-insensitively:
Word 1: text between "In the silent hum of " and ","
Word 2: text between "each pulse of " and " threading"
Word 3: text between "Beyond the wall of " and ","
0x44a8db–0x44a99b extracts the fourth word differently:
Find " of distant servers"
Walk backward to the previous whitespace
Require the 4 bytes before the word to be "the "
Use the word after "the " as Word 4
The four words are then matched to corresponding numbers, which combine to form the IPv4 address hosting the server.
Here’s what the C2 conversion looks like with the key:
Black Lotus Labs’ write-up lists all the C2 IP addresses, plus when they were first and last seen, so be sure to check that out.
More AI infrastructure = larger attack surface
As enterprises increasingly use AI in their operations, they also expand their attack surface. And, as we have repeatedly seen, security remains an afterthought in AI deployments.
“The Canto Incognito campaign appears to be relatively unique in its targeting of multiple AI-related services,” the researchers told The Register. “Other notable campaigns this year, including the LiteLLM supply chain compromise, focused on a single service and impacted roughly 2,500 victims, according to open sources. The collection of more than 3,000 PoeLLM victims appears to exhibit multiple vulnerable services at any given time.”
For comparison: The LiteLLM supply chain attack, which began with a compromised Trivy build, potentially exposed more than 2,500 companies and 434,000 CI/CD pipelines worldwide, according to CloudSEK security researchers.
The PoeLLM malware developer “has been extremely successful in identifying vulnerable servers, deploying exploits, and conscripting victims to continue expanding the campaign,” Black Lotus Labs said. “If the actor had only focused on one or two vulnerabilities, the potential victim pool might have quickly dried up, but the expanding scope allowed for a bigger, more powerful (and more profitable) botnet.”
They told us they expect to see more of these types of attacks in the near future.
“AI makes it easier to deploy tools like LiteLLM, Ollama, or Gotenberg, but AI isn't always checking to make sure those services are patched and protected from attackers,” the researchers said. “As more AI-enabled servers come online, malware like PoeLLM will continue to spread.”®
Originally published by The Register. © The Register.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-07 16:01 UTC
Related stories
- Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
The Hacker News · 2026-10-07
- PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
The Hacker News · 2026-10-07
- PoeLLM malware infects exposed AI servers in cryptomining attacks
BleepingComputer · 2026-10-07
- Attackers Hide AI Prompt Injections Inside Phishing Emails
Infosecurity Magazine · 2026-10-07
- Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
The Hacker News · 2026-10-07