A sophisticated malware campaign dubbed Canto Incognito has compromised over 3,400 AI servers since April 2026, using an innovative technique that hides command-and-control addresses within poetry hosted on GitHub. The PoeLLM malware targets exposed AI infrastructure like LiteLLM and Ollama to mine cryptocurrency while turning victims into vulnerability scanners.

Adversarial Poetry Emerges as Novel AI Security Threat

PoeLLM malware has introduced a groundbreaking attack method that weaponizes poetry to compromise AI security infrastructure. Tracked by Lumen's Black Lotus Labs, this campaign represents the first real-world deployment of adversarial poetry—an AI jailbreak technique that disguises harmful prompts within verse to bypass LLM safety guardrails

1

. Since April 2026, the malware infects AI servers at an alarming rate, compromising more than 3,400 systems primarily across the United States and Western Europe

3

. At its peak in mid-June, nearly 2,200 servers were affected, with approximately 800 active infections per day

2

.

Source: BleepingComputer

Source: BleepingComputer

The financially motivated campaign, dubbed Canto Incognito by Black Lotus Labs, targets vulnerable AI infrastructure including internet-facing deployments of LiteLLM and Ollama, along with Gotenberg PDF converter and Gitea development platforms

1

. Researchers attribute the operation to an Italian-speaking attacker operating under the GitHub username "ejejejdfbbebe," with moderate confidence based on Italian-language comments within the malware code and netflow analysis indicating Italy-based infrastructure

2

.

How Command-and-Control Servers Hide in Plain Sight

The PoeLLM malware employs an unprecedented method to locate its command-and-control servers through a poem titled "On the Nature of Connection" hosted in a GitHub repository disguised as a fork of the nodejs.org website source code

1

. The malware extracts four specific words or phrases from the poem using hard-coded parsing logic, then converts them to numbers via an embedded dictionary to generate IPv4 addresses for command-and-control servers

2

.

"To anyone who comes across it, this is simply a poem on GitHub. It has no links, no files to download, no encrypted text that could easily be flagged as malicious," Black Lotus Labs researchers explained

1

. The poem has been modified 11 times since its initial commit on April 13, 2026, with each update changing the C2 address. Ryan English, information security engineer at Lumen Technologies, noted that "each time they set up a new C2, they change a few words in the poem, and the malware derives the address from the key associated with those words"

3

.

Cryptocurrency Mining Operations Target GPU Hardware

The crypto mining botnet deploys XMRig and Iron miners on compromised systems, connecting victims to Kryptex, a Russian cryptocurrency mining service

3

. AI infrastructure proves particularly valuable for cryptocurrency mining because these systems typically run on powerful GPU hardware clusters optimized for computational workloads

2

. The malware specifically targets enterprise AI deployments that are often poorly configured and exposed online, making them ideal candidates for illicit mining operations

3

.

Source: Hacker News

Source: Hacker News

Beyond cryptocurrency mining, PoeLLM transforms infected systems into vulnerability scanners and exploit servers, creating a self-propagating botnet

1

. Compromised hosts scan ports 3000 and 4000 associated with Gotenberg and LiteLLM, attempting to exploit CVE-2026-42271—a vulnerability in LiteLLM's MCP server test endpoints that can be chained with CVE-2026-48710 for unauthenticated remote code execution

2

.

Ivanti Sentry and Expanding Attack Surface

Black Lotus Labs first discovered the PoeLLM malware while investigating Ivanti Sentry vulnerability CVE-2026-10520

1

. In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[.]122, and shortly afterward began scanning for additional vulnerable devices

1

. Infrastructure analysis revealed that several command-and-control servers featured vulnerable router administration interfaces, suggesting the attacker repurposes compromised routers within the attacks

2

.

Recent traffic patterns toward SSH and other login portals indicate the campaign may be experimenting with distributed brute-force attacks, though the maturity of this capability remains uncertain

3

. The malware's remote-shell functionality, combined with HTTP/S scanning and exploit deployment capabilities, creates a versatile toolkit for expanding the botnet's reach

2

.

Protecting Vulnerable AI Infrastructure From Future Attacks

System administrators must act immediately to secure exposed AI services against PoeLLM malware and similar threats. Black Lotus Labs recommends applying the latest security updates, reducing public internet exposure for critical assets, and restricting external access only to trusted IP addresses

2

. Organizations should inspect network monitoring logs for connections to known indicators of compromise shared by security researchers.

Source: The Register

Source: The Register

The emergence of adversarial poetry as an attack vector signals a troubling evolution in malware obfuscation techniques. As AI infrastructure becomes increasingly valuable—not only for computational power but also for the sensitive data these systems process—organizations must prioritize hardening their LLM deployments. Watch for continued innovation in C2 communication methods that leverage legitimate platforms like GitHub to evade detection. The PoeLLM campaign demonstrates how attackers adapt to exploit the intersection of AI adoption and security oversight, making proactive defense essential for organizations deploying AI systems.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved