3 Sources
[1]
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet. This is the first case of "adversarial poetry" - an AI jailbreak
[2]
PoeLLM malware infects exposed AI servers in cryptomining attacks
A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. The malware features an uncommon method to retrieve command-and-control (C2) addresses by extracting keywords in a poem hosted on GitHub. Researchers at
[3]
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially
Share
Copy Link
A sophisticated malware campaign dubbed Canto Incognito has compromised over 3,400 AI servers since April 2026, using an innovative technique that hides command-and-control addresses within poetry hosted on GitHub. The PoeLLM malware targets exposed AI infrastructure like LiteLLM and Ollama to mine cryptocurrency while turning victims into vulnerability scanners.
PoeLLM malware has introduced a groundbreaking attack method that weaponizes poetry to compromise AI security infrastructure. Tracked by Lumen's Black Lotus Labs, this campaign represents the first real-world deployment of adversarial poetry—an AI jailbreak technique that disguises harmful prompts within verse to bypass LLM safety guardrails
1
. Since April 2026, the malware infects AI servers at an alarming rate, compromising more than 3,400 systems primarily across the United States and Western Europe3
. At its peak in mid-June, nearly 2,200 servers were affected, with approximately 800 active infections per day2
.
Source: BleepingComputer
The financially motivated campaign, dubbed Canto Incognito by Black Lotus Labs, targets vulnerable AI infrastructure including internet-facing deployments of LiteLLM and Ollama, along with Gotenberg PDF converter and Gitea development platforms
1
. Researchers attribute the operation to an Italian-speaking attacker operating under the GitHub username "ejejejdfbbebe," with moderate confidence based on Italian-language comments within the malware code and netflow analysis indicating Italy-based infrastructure2
.The PoeLLM malware employs an unprecedented method to locate its command-and-control servers through a poem titled "On the Nature of Connection" hosted in a GitHub repository disguised as a fork of the nodejs.org website source code
1
. The malware extracts four specific words or phrases from the poem using hard-coded parsing logic, then converts them to numbers via an embedded dictionary to generate IPv4 addresses for command-and-control servers2
."To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious," Black Lotus Labs researchers explained
1
. The poem has been modified 11 times since its initial commit on April 13, 2026, with each update changing the C2 address. Ryan English, information security engineer at Lumen Technologies, noted that "each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words"3
.The crypto mining botnet deploys XMRig and Iron miners on compromised systems, connecting victims to Kryptex, a Russian cryptocurrency mining service
3
. AI infrastructure proves particularly valuable for cryptocurrency mining because these systems typically run on powerful GPU hardware clusters optimized for computational workloads2
. The malware specifically targets enterprise AI deployments that are often poorly configured and exposed online, making them ideal candidates for illicit mining operations3
.
Source: Hacker News
Beyond cryptocurrency mining, PoeLLM transforms infected systems into vulnerability scanners and exploit servers, creating a self-propagating botnet
1
. Compromised hosts scan ports 3000 and 4000 associated with Gotenberg and LiteLLM, attempting to exploit CVE-2026-42271—a vulnerability in LiteLLM's MCP server test endpoints that can be chained with CVE-2026-48710 for unauthenticated remote code execution2
.Related Stories
Black Lotus Labs first discovered the PoeLLM malware while investigating Ivanti Sentry vulnerability CVE-2026-10520
1
. In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122, and shortly afterward began scanning for additional vulnerable devices1
. Infrastructure analysis revealed that several command-and-control servers featured vulnerable router administration interfaces, suggesting the attacker repurposes compromised routers within the attacks2
.Recent traffic patterns toward SSH and other login portals indicate the campaign may be experimenting with distributed brute-force attacks, though the maturity of this capability remains uncertain
3
. The malware's remote-shell functionality, combined with HTTP/S scanning and exploit deployment capabilities, creates a versatile toolkit for expanding the botnet's reach2
.System administrators must act immediately to secure exposed AI services against PoeLLM malware and similar threats. Black Lotus Labs recommends applying the latest security updates, reducing public internet exposure for critical assets, and restricting external access only to trusted IP addresses
2
. Organizations should inspect network monitoring logs for connections to known indicators of compromise shared by security researchers.
Source: The Register
The emergence of adversarial poetry as an attack vector signals a troubling evolution in malware obfuscation techniques. As AI infrastructure becomes increasingly valuable—not only for computational power but also for the sensitive data these systems process—organizations must prioritize hardening their LLM deployments. Watch for continued innovation in C2 communication methods that leverage legitimate platforms like GitHub to evade detection. The PoeLLM campaign demonstrates how attackers adapt to exploit the intersection of AI adoption and security oversight, making proactive defense essential for organizations deploying AI systems.
Summarized by
Navi
[2]
28 May 2026•Technology

04 Sept 2025•Technology

01 Jul 2026•Technology

1
Technology

2
Policy and Regulation

3
Policy and Regulation
