cd /news/ai-safety/poetry-is-the-new-ai-security-threat… · home › topics › ai-safety › article
[ARTICLE · art-147095] src=theregister.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers

Lumen's Black Lotus Labs reported that the PoeLLM malware campaign, which hides malicious commands in an AI-written poem posted to a GitHub repository, has infected more than 3,000 servers since April, primarily in the US and Western Europe, peaking at over 800 active infections per day. The researchers attributed the financially motivated campaign, named Canto Incognito, to an Italian-speaking attacker and said it is the first real-world case of "adversarial poetry," an AI jailbreak technique that turns harmful prompts into poems to bypass LLM safety guardrails. Victims mostly ran vulnerable internet-facing versions of LiteLLM and Ollama, plus hundreds running Gotenberg and Gitea, and the malware deploys XMRig and Iron miners connected to Kryptex mining infrastructure while turning compromised machines into vulnerability scanners and exploit servers.

by read5 min views3 publishedOct 7, 2026
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
Image: The Register

A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet.

This is the first case of “adversarial poetry” - an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails - that Lumen’s Black Lotus Labs, which has been tracking the PoeLLM malware, has seen in real-world attacks.

“This is a first for us,” the researchers told The Register via email.

REG AD

“While we can't get inside the threat actor's head, we think the attacker might have used a poem because it serves as a perfect vehicle for hiding an important message,” they added. “To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models. There would be no reason for any security researcher to identify this poem as malicious - or know about the IP address hidden within it - unless they had access to the malware referencing it.”

REG AD

PoeLLM malware has been active since at least April, impacting more than 3,000 servers primarily located in the US and Western Europe, and it continues to infect new victims. At its peak, the malware infected more than 800 active servers per day.

The malware abuses - and scans for - open source AI systems and services. Most of the victims were running vulnerable, internet-facing versions of LiteLLM and Ollama. Additionally, hundreds of victims were running Gotenberg, a PDF converter, and software development platform Gitea.

In addition to these open source tools, the attacker may have targeted commercial software including Ivanti Sentry. The threat hunters first spotted the PoeLLM malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520.

“In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122,” according to a Wednesday report shared with The Register. “Shortly after contacting this C2, the Ivanti Sentry victim began scanning for other vulnerable devices.”

How adversarial poetry works

Black Lotus Labs attributed the PoeLLM malware to an Italian-speaking criminal, and named the financially motivated campaign Canto Incognito because it hides the malicious commands in a poem posted to a GitHub repository.

“Comments within the malware and on the attacker’s GitHub pages are in Italian, and netflow analyzed by Black Lotus Labs suggests that the attacker is located in Italy,” the threat-hunters told us, adding that they believe the campaign targets AI systems and that the poem itself was written by AI.

The malware deploys XMRig and Iron miners, and connects victims to Kryptex mining infrastructure.

REG AD

In addition to using compromised GPU hardware powering AI workloads to mine cryptocurrency, PoeLLM also turns victims' machines into vulnerability scanners and exploit servers, which allows the attacker to compromise even more vulnerable systems.

The researchers’ investigation indicates that the cryptojacking miscreant - aka GitHub user “ejejejdfbbebe” - made the first GitHub commit with the adversarial poem on April 13. The repo is a fork of the nodejs.org website source code, and the file is called “dash.css.” Inside the file, there’s a poem titled “On the Nature of Connection,” which has been updated 11 times since its initial commit. Here’s the most current version, as of September:

In the silent hum of driver, the machines begin to speak,

Each pulse of diode threading light through copper veins.

we taught the dark to carry meaning, byte by byte —

A language built from lightning, cold and clean.

Beyond the wall of encryption, a signal finds its way,

the tick of distant servers answering back.

REG AD

Data moves like water through the cracks of ordered thought,

and somewhere in the code, the world stays on track.

Here’s the adversarial piece: the malware finds its current command-and-control (C2) server from keywords in the poem, and when the operator changes the poem, the infected systems find the new C2 location. It does this by parsing the poem, extracting certain words and phrases, and then converting them to numbers using a hard-coded dictionary in the body of the malware.

Black Lotus Labs says the logic for C2 discovery works like this:

The function “extract_poem_phrase_field” extracts three words/phrases from the body of the poem, case-insensitively:

Word 1: text between "In the silent hum of " and ","

Word 2: text between "each pulse of " and " threading"

Word 3: text between "Beyond the wall of " and ","

0x44a8db–0x44a99b extracts the fourth word differently:

Find " of distant servers"

Walk backward to the previous whitespace

Require the 4 bytes before the word to be "the "

Use the word after "the " as Word 4

The four words are then matched to corresponding numbers, which combine to form the IPv4 address hosting the server.

Here’s what the C2 conversion looks like with the key:

Black Lotus Labs’ write-up lists all the C2 IP addresses, plus when they were first and last seen, so be sure to check that out.

“The Canto Incognito campaign appears to be relatively unique in its targeting of multiple AI-related services,” the researchers told The Register. “Other notable campaigns this year, including the LiteLLM supply chain compromise, focused on a single service and impacted roughly 2,500 victims, according to open sources. The collection of more than 3,000 PoeLLM victims appears to exhibit multiple vulnerable services at any given time.”

The PoeLLM malware developer “has been extremely successful in identifying vulnerable servers, deploying exploits, and conscripting victims to continue expanding the campaign,” Black Lotus Labs said. “If the actor had only focused on one or two vulnerabilities, the potential victim pool might have quickly dried up, but the expanding scope allowed for a bigger, more powerful (and more profitable) botnet.”

They told us they expect to see more of these types of attacks in the near future.

“AI makes it easier to deploy tools like LiteLLM, Ollama, or Gotenberg, but AI isn't always checking to make sure those services are patched and protected from attackers,” the researchers said. “As more AI-enabled servers come online, malware like PoeLLM will continue to spread.”®

── more in #ai-safety 4 stories · sorted by recency
── more on @lumen 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/poetry-is-the-new-ai…] indexed:0 read:5min 2026-10-07 · —