{"slug": "poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers", "title": "Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers", "summary": "Lumen's Black Lotus Labs reported that the PoeLLM malware campaign, which hides malicious commands in an AI-written poem posted to a GitHub repository, has infected more than 3,000 servers since April, primarily in the US and Western Europe, peaking at over 800 active infections per day. The researchers attributed the financially motivated campaign, named Canto Incognito, to an Italian-speaking attacker and said it is the first real-world case of \"adversarial poetry,\" an AI jailbreak technique that turns harmful prompts into poems to bypass LLM safety guardrails. Victims mostly ran vulnerable internet-facing versions of LiteLLM and Ollama, plus hundreds running Gotenberg and Gitea, and the malware deploys XMRig and Iron miners connected to Kryptex mining infrastructure while turning compromised machines into vulnerability scanners and exploit servers.", "body_md": "A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet.\n\nThis is the first case of “adversarial poetry” - an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails - that Lumen’s Black Lotus Labs, which has been tracking the PoeLLM malware, has seen in real-world attacks.\n\n“This is a first for us,” the researchers told The Register via email.\n\nREG AD\n\n“While we can't get inside the threat actor's head, we think the attacker might have used a poem because it serves as a perfect vehicle for hiding an important message,” they added. “To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious, even by advanced models. There would be no reason for any security researcher to identify this poem as malicious - or know about the IP address hidden within it - unless they had access to the malware referencing it.”\n\nREG AD\n\nPoeLLM malware has been active since at least April, impacting more than 3,000 servers primarily located in the US and Western Europe, and it continues to infect new victims. At its peak, the malware infected more than 800 active servers per day.\n\nThe malware abuses - and scans for - open source AI systems and services. Most of the victims were running vulnerable, internet-facing versions of LiteLLM and Ollama. Additionally, hundreds of victims were running Gotenberg, a PDF converter, and software development platform Gitea.\n\nIn addition to these open source tools, the attacker may have targeted commercial software including Ivanti Sentry. The threat hunters first spotted the PoeLLM malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520.\n\n“In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122,” according to a Wednesday report shared with The Register. “Shortly after contacting this C2, the Ivanti Sentry victim began scanning for other vulnerable devices.”\n\nHow adversarial poetry works\n\nBlack Lotus Labs attributed the PoeLLM malware to an Italian-speaking criminal, and named the financially motivated campaign Canto Incognito because it hides the malicious commands in a poem posted to a GitHub repository.\n\n“Comments within the malware and on the attacker’s GitHub pages are in Italian, and netflow analyzed by Black Lotus Labs suggests that the attacker is located in Italy,” the threat-hunters told us, adding that they believe the campaign targets AI systems and that the poem itself was written by AI.\n\nThe malware deploys XMRig and Iron miners, and connects victims to Kryptex mining infrastructure.\n\nREG AD\n\nIn addition to using compromised GPU hardware powering AI workloads to mine cryptocurrency, PoeLLM also turns victims' machines into vulnerability scanners and exploit servers, which allows the attacker to compromise even more vulnerable systems.\n\nThe researchers’ investigation indicates that the cryptojacking miscreant - aka GitHub user “ejejejdfbbebe” - made the first GitHub commit with the adversarial poem on April 13. The repo is a fork of the nodejs.org website source code, and the file is called “dash.css.” Inside the file, there’s a poem titled “On the Nature of Connection,” which has been updated 11 times since its initial commit. Here’s the most current version, as of September:\n\nIn the silent hum of driver, the machines begin to speak,\n\nEach pulse of diode threading light through copper veins.\n\nwe taught the dark to carry meaning, byte by byte —\n\nA language built from lightning, cold and clean.\n\nBeyond the wall of encryption, a signal finds its way,\n\nthe tick of distant servers answering back.\n\nREG AD\n\nData moves like water through the cracks of ordered thought,\n\nand somewhere in the code, the world stays on track.\n\nHere’s the adversarial piece: the malware finds its current command-and-control (C2) server from keywords in the poem, and when the operator changes the poem, the infected systems find the new C2 location. It does this by parsing the poem, extracting certain words and phrases, and then converting them to numbers using a hard-coded dictionary in the body of the malware.\n\nBlack Lotus Labs says the logic for C2 discovery works like this:\n\nThe function “extract_poem_phrase_field” extracts three words/phrases from the body of the poem, case-insensitively:\n\nWord 1: text between \"In the silent hum of \" and \",\"\n\nWord 2: text between \"each pulse of \" and \" threading\"\n\nWord 3: text between \"Beyond the wall of \" and \",\"\n\n0x44a8db–0x44a99b extracts the fourth word differently:\n\nFind \" of distant servers\"\n\nWalk backward to the previous whitespace\n\nRequire the 4 bytes before the word to be \"the \"\n\nUse the word after \"the \" as Word 4\n\nThe four words are then matched to corresponding numbers, which combine to form the IPv4 address hosting the server.\n\nHere’s what the C2 conversion looks like with the key:\n\nBlack Lotus Labs’ write-up lists all the C2 IP addresses, plus when they were first and last seen, so be sure to check that out.\n\n“The Canto Incognito campaign appears to be relatively unique in its targeting of multiple AI-related services,” the researchers told The Register. “Other notable campaigns this year, including the LiteLLM supply chain compromise, focused on a single service and impacted roughly 2,500 victims, according to open sources. The collection of more than 3,000 PoeLLM victims appears to exhibit multiple vulnerable services at any given time.”\n\nThe PoeLLM malware developer “has been extremely successful in identifying vulnerable servers, deploying exploits, and conscripting victims to continue expanding the campaign,” Black Lotus Labs said. “If the actor had only focused on one or two vulnerabilities, the potential victim pool might have quickly dried up, but the expanding scope allowed for a bigger, more powerful (and more profitable) botnet.”\n\nThey told us they expect to see more of these types of attacks in the near future.\n\n“AI makes it easier to deploy tools like LiteLLM, Ollama, or Gotenberg, but AI isn't always checking to make sure those services are patched and protected from attackers,” the researchers said. “As more AI-enabled servers come online, malware like PoeLLM will continue to spread.”®", "url": "https://wpnews.pro/news/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers", "canonical_source": "https://www.theregister.com/security/2026/10/07/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers/5301672", "published_at": "2026-10-07 16:01:08+00:00", "updated_at": "2026-10-07 19:20:19.316130+00:00", "lang": "en", "topics": ["ai-safety", "artificial-intelligence", "ai-infrastructure", "large-language-models"], "entities": ["Lumen", "Black Lotus Labs", "PoeLLM", "LiteLLM", "Ollama", "Gotenberg", "Gitea", "Ivanti Sentry"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers", "markdown": "https://wpnews.pro/news/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers.md", "text": "https://wpnews.pro/news/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers.txt", "jsonld": "https://wpnews.pro/news/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers.jsonld"}}