Threat
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
First reported theregister.com
Page published · Page updated
Earliest dated coverage: 7 Oct 2026 · First observed: 7 Oct 2026 · Latest dated coverage: 7 Oct 2026
Coverage timeline
Single-source incident — one report is available.
Why it matters
PoeLLM is the first observed real-world use of the adversarial-poetry jailbreak technique weaponized at scale against enterprise AI infrastructure, showing that stylistic prompt obfuscation can both evade model guardrails and conceal malicious C2 instructions from defenders.
PoeLLM malware, tracked by Lumen's Black Lotus Labs, has infected more than 3,000 internet-facing AI servers since April 2026, using an 'adversarial poetry' jailbreak — a poem hosted on GitHub that hides a C2 IP address and tricks LLMs into bypassing safety guardrails. The campaign scans for and compromises vulnerable LiteLLM, Ollama, Gotenberg, and Gitea deployments (and possibly Ivanti Sentry via CVE-2026-10520) to mine cryptocurrency and expand a botnet.
Summary
Lumen's Black Lotus Labs has uncovered a financially motivated cryptojacking campaign it calls Canto Incognito, which deploys malware tracked as PoeLLM. Since April 2026 the operation has infected more than 3,000 servers, primarily in the US and Western Europe, peaking at over 800 new infections per day.[0]
The campaign is notable for being the first real-world use Black Lotus Labs has observed of 'adversarial poetry' — a technique that hides the malware's command-and-control address inside an AI-written poem posted to GitHub. The malware parses keywords from the poem and converts them to numbers to resolve the current C2 IP, letting the operator rotate infrastructure simply by editing the verse.[0]
PoeLLM targets a broad set of AI-related and open-source services — most victims ran exposed LiteLLM and Ollama instances, with hundreds running Gotenberg and Gitea, and the actor may also have exploited Ivanti Sentry (CVE-2026-10520). Compromised machines mine Monero via XMRig and Iron miners connected to Kryptex infrastructure, and are also conscripted as scanners and exploit servers to expand the botnet.[0]
Attack chain
- Reconnaissance / Scanning: PoeLLM scans the internet for vulnerable, internet-facing AI and open-source services, chiefly LiteLLM and Ollama, plus Gotenberg, Gitea and possibly Ivanti Sentry (CVE-2026-10520).[0]
- C2 resolution via adversarial poem: The malware retrieves a poem ('On the Nature of Connection') from a GitHub repo, extracts specific words/phrases case-insensitively, and converts them to numbers via a hard-coded dictionary to assemble the IPv4 address of its current C2 server. Changing the poem redirects infected systems to new C2 infrastructure.[0]
- Command and control: A compromised Ivanti Sentry victim contacted the dedicated C2 at 5.78.73.122 in early June 2026, after which it began scanning for additional vulnerable devices.[0]
- Cryptomining payload: PoeLLM deploys XMRig and Iron miners and connects victims — including compromised GPU hardware powering AI workloads — to Kryptex mining infrastructure.[0]
- Propagation: Infected machines are turned into vulnerability scanners and exploit servers, allowing the attacker to compromise further systems and grow the botnet.[0]
Disclosure timeline
| Date | Event |
|---|---|
| 2025-11-19 | Academic paper on adversarial poetry as a universal single-turn LLM jailbreak first submitted to arXiv (last revised 2026-01-16).[1] |
| 2026-04-13 | GitHub user 'ejejejdfbbebe' makes the first commit containing the adversarial poem, in a fork of the nodejs.org source, in a file named dash.css.[0] |
| 2026-04 (since) | PoeLLM malware active and infecting servers.[0] |
| 2026-06 (early) | A compromised Ivanti Sentry victim contacts the C2 at 5.78.73.122 and begins scanning for other vulnerable devices.[0] |
| 2026-09 | Most current version of the poem observed; the poem has been updated 11 times since its initial commit.[0] |
| 2026-10-07 | Black Lotus Labs publishes its Canto Incognito report and The Register reports on the campaign.[0] |
Actor profile
Canto Incognito (PoeLLM operator / GitHub user 'ejejejdfbbebe')
Black Lotus Labs attributes the malware to an Italian-speaking, financially motivated criminal. Comments within the malware and on the attacker's GitHub pages are in Italian, and netflow analysis suggests the actor is located in Italy. The campaign targets AI-related services, and the operator uses an AI-written poem for covert C2 redirection, deploying cryptominers and conscripting victims to expand the botnet.[0]
How it works
The adversarial component is in how PoeLLM resolves its C2. The function extract_poem_phrase_field pulls three words/phrases from the poem case-insensitively: the text between 'In the silent hum of ' and ',', between 'each pulse of ' and ' threading', and between 'Beyond the wall of ' and ','. A fourth routine (0x44a8db–0x44a99b) finds ' of distant servers', walks backward to the previous whitespace, requires the preceding 4 bytes to be 'the ', and uses the word after 'the ' as Word 4. The four words are matched to numbers via a hard-coded dictionary and combined to form the C2 IPv4 address.[0]
Because the C2 location is encoded in ordinary-looking poem text on GitHub — no links, files, or encrypted blobs — the content evades signature- and model-based detection; the operator can rotate C2 infrastructure merely by editing the poem, which has already been updated 11 times.[0]
The broader enabling technique, 'adversarial poetry,' is a documented universal single-turn jailbreak that converts harmful prompts into verse, achieving attack-success rates up to 18 times higher than prose baselines and exceeding 90% for some providers across 25 frontier LLMs.[1]
Affected versions and patch status
| Product | Affected | Patch status |
|---|---|---|
| LiteLLM | Vulnerable, internet-facing versions (most common victim service) | Not specified in evidence[0] |
| Ollama | Vulnerable, internet-facing versions (most common victim service) | Not specified in evidence[0] |
| Gotenberg (PDF converter) | Running on hundreds of victim servers | Not specified in evidence[0] |
| Gitea | Running on hundreds of victim servers | Not specified in evidence[0] |
| Ivanti Sentry | CVE-2026-10520; possibly targeted, confirmed in at least one compromised victim | Not specified in evidence[0] |
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| ip | 5.78.73.122 | Dedicated PoeLLM C2 server contacted by a compromised Ivanti Sentry victim in early June 2026, after which the victim began scanning for other vulnerable devices.[0] |
| other | GitHub user 'ejejejdfbbebe' | Attacker GitHub persona that made the first commit of the adversarial poem on April 13, 2026, in a fork of the nodejs.org source.[0] |
| file-path | dash.css | File inside the attacker's nodejs.org-fork GitHub repo containing the poem 'On the Nature of Connection' used for C2 resolution.[0] |
| cve | CVE-2026-10520 | Ivanti Sentry vulnerability associated with at least one PoeLLM victim; investigation of this CVE led to discovery of the malware.[0] |
Key takeaways
- Canto Incognito is the first observed real-world use of adversarial poetry — not as an LLM jailbreak but as a covert C2 steganography channel encoded in a GitHub-hosted poem.[0]
- Targeting multiple AI-related services simultaneously (LiteLLM, Ollama, Gotenberg, Gitea) let the actor sustain a victim pool far larger than single-service campaigns, exceeding 3,000 victims.[0]
- The rapid growth of exposed, unpatched AI infrastructure is creating a lucrative target set for cryptojacking botnets, a trend researchers expect to continue.[0]
Defensive actions
- Patch and remove internet exposure of LiteLLM, Ollama, Gotenberg, Gitea and Ivanti Sentry instances.: These services were the most common PoeLLM victim software; the researchers note AI deployments often go unpatched, expanding attack surface.[0]
- Block and hunt for communications with the C2 IP 5.78.73.122 and review Black Lotus Labs' full C2 list.: Victims contact dedicated C2 servers to receive commands; Black Lotus Labs published all C2 IPs with first/last-seen dates.[0]
- Monitor GPU/AI workload hosts for unexpected mining activity and outbound scanning behaviour.: PoeLLM deploys XMRig and Iron miners on compromised GPU hardware and turns victims into scanners and exploit servers.[0]
- Treat innocuous-looking external content (e.g., poems/CSS files in public repos) as potential covert C2 channels in detection logic.: The malware encodes its C2 IP in an ordinary-looking GitHub poem with no links or files, defeating conventional malicious-content detection.[0]