Threat

Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers

Page published · Page updated

Dossier

Earliest dated coverage: 7 Oct 2026 · First observed: 7 Oct 2026 · Latest dated coverage: 7 Oct 2026

Coverage timeline

discovered lumen.com primary 7 Oct 2026theregister.com

Single-source incident — one report is available.

Why it matters

PoeLLM is the first observed real-world use of the adversarial-poetry jailbreak technique weaponized at scale against enterprise AI infrastructure, showing that stylistic prompt obfuscation can both evade model guardrails and conceal malicious C2 instructions from defenders.

PoeLLM malware, tracked by Lumen's Black Lotus Labs, has infected more than 3,000 internet-facing AI servers since April 2026, using an 'adversarial poetry' jailbreak — a poem hosted on GitHub that hides a C2 IP address and tricks LLMs into bypassing safety guardrails. The campaign scans for and compromises vulnerable LiteLLM, Ollama, Gotenberg, and Gitea deployments (and possibly Ivanti Sentry via CVE-2026-10520) to mine cryptocurrency and expand a botnet.

campaign

Summary

Lumen's Black Lotus Labs has uncovered a financially motivated cryptojacking campaign it calls Canto Incognito, which deploys malware tracked as PoeLLM. Since April 2026 the operation has infected more than 3,000 servers, primarily in the US and Western Europe, peaking at over 800 new infections per day.[0]

The campaign is notable for being the first real-world use Black Lotus Labs has observed of 'adversarial poetry' — a technique that hides the malware's command-and-control address inside an AI-written poem posted to GitHub. The malware parses keywords from the poem and converts them to numbers to resolve the current C2 IP, letting the operator rotate infrastructure simply by editing the verse.[0]

PoeLLM targets a broad set of AI-related and open-source services — most victims ran exposed LiteLLM and Ollama instances, with hundreds running Gotenberg and Gitea, and the actor may also have exploited Ivanti Sentry (CVE-2026-10520). Compromised machines mine Monero via XMRig and Iron miners connected to Kryptex infrastructure, and are also conscripted as scanners and exploit servers to expand the botnet.[0]

Attack chain

  1. Reconnaissance / Scanning: PoeLLM scans the internet for vulnerable, internet-facing AI and open-source services, chiefly LiteLLM and Ollama, plus Gotenberg, Gitea and possibly Ivanti Sentry (CVE-2026-10520).[0]
  2. C2 resolution via adversarial poem: The malware retrieves a poem ('On the Nature of Connection') from a GitHub repo, extracts specific words/phrases case-insensitively, and converts them to numbers via a hard-coded dictionary to assemble the IPv4 address of its current C2 server. Changing the poem redirects infected systems to new C2 infrastructure.[0]
  3. Command and control: A compromised Ivanti Sentry victim contacted the dedicated C2 at 5.78.73.122 in early June 2026, after which it began scanning for additional vulnerable devices.[0]
  4. Cryptomining payload: PoeLLM deploys XMRig and Iron miners and connects victims — including compromised GPU hardware powering AI workloads — to Kryptex mining infrastructure.[0]
  5. Propagation: Infected machines are turned into vulnerability scanners and exploit servers, allowing the attacker to compromise further systems and grow the botnet.[0]

Disclosure timeline

DateEvent
2025-11-19Academic paper on adversarial poetry as a universal single-turn LLM jailbreak first submitted to arXiv (last revised 2026-01-16).[1]
2026-04-13GitHub user 'ejejejdfbbebe' makes the first commit containing the adversarial poem, in a fork of the nodejs.org source, in a file named dash.css.[0]
2026-04 (since)PoeLLM malware active and infecting servers.[0]
2026-06 (early)A compromised Ivanti Sentry victim contacts the C2 at 5.78.73.122 and begins scanning for other vulnerable devices.[0]
2026-09Most current version of the poem observed; the poem has been updated 11 times since its initial commit.[0]
2026-10-07Black Lotus Labs publishes its Canto Incognito report and The Register reports on the campaign.[0]

Actor profile

Canto Incognito (PoeLLM operator / GitHub user 'ejejejdfbbebe')

Black Lotus Labs attributes the malware to an Italian-speaking, financially motivated criminal. Comments within the malware and on the attacker's GitHub pages are in Italian, and netflow analysis suggests the actor is located in Italy. The campaign targets AI-related services, and the operator uses an AI-written poem for covert C2 redirection, deploying cryptominers and conscripting victims to expand the botnet.[0]

How it works

The adversarial component is in how PoeLLM resolves its C2. The function extract_poem_phrase_field pulls three words/phrases from the poem case-insensitively: the text between 'In the silent hum of ' and ',', between 'each pulse of ' and ' threading', and between 'Beyond the wall of ' and ','. A fourth routine (0x44a8db–0x44a99b) finds ' of distant servers', walks backward to the previous whitespace, requires the preceding 4 bytes to be 'the ', and uses the word after 'the ' as Word 4. The four words are matched to numbers via a hard-coded dictionary and combined to form the C2 IPv4 address.[0]

Because the C2 location is encoded in ordinary-looking poem text on GitHub — no links, files, or encrypted blobs — the content evades signature- and model-based detection; the operator can rotate C2 infrastructure merely by editing the poem, which has already been updated 11 times.[0]

The broader enabling technique, 'adversarial poetry,' is a documented universal single-turn jailbreak that converts harmful prompts into verse, achieving attack-success rates up to 18 times higher than prose baselines and exceeding 90% for some providers across 25 frontier LLMs.[1]

Affected versions and patch status

ProductAffectedPatch status
LiteLLMVulnerable, internet-facing versions (most common victim service)Not specified in evidence[0]
OllamaVulnerable, internet-facing versions (most common victim service)Not specified in evidence[0]
Gotenberg (PDF converter)Running on hundreds of victim serversNot specified in evidence[0]
GiteaRunning on hundreds of victim serversNot specified in evidence[0]
Ivanti SentryCVE-2026-10520; possibly targeted, confirmed in at least one compromised victimNot specified in evidence[0]

Indicators of Compromise

TypeIndicatorContext
ip5.78.73.122Dedicated PoeLLM C2 server contacted by a compromised Ivanti Sentry victim in early June 2026, after which the victim began scanning for other vulnerable devices.[0]
otherGitHub user 'ejejejdfbbebe'Attacker GitHub persona that made the first commit of the adversarial poem on April 13, 2026, in a fork of the nodejs.org source.[0]
file-pathdash.cssFile inside the attacker's nodejs.org-fork GitHub repo containing the poem 'On the Nature of Connection' used for C2 resolution.[0]
cveCVE-2026-10520Ivanti Sentry vulnerability associated with at least one PoeLLM victim; investigation of this CVE led to discovery of the malware.[0]

Key takeaways

  • Canto Incognito is the first observed real-world use of adversarial poetry — not as an LLM jailbreak but as a covert C2 steganography channel encoded in a GitHub-hosted poem.[0]
  • Targeting multiple AI-related services simultaneously (LiteLLM, Ollama, Gotenberg, Gitea) let the actor sustain a victim pool far larger than single-service campaigns, exceeding 3,000 victims.[0]
  • The rapid growth of exposed, unpatched AI infrastructure is creating a lucrative target set for cryptojacking botnets, a trend researchers expect to continue.[0]

Defensive actions

  • Patch and remove internet exposure of LiteLLM, Ollama, Gotenberg, Gitea and Ivanti Sentry instances.: These services were the most common PoeLLM victim software; the researchers note AI deployments often go unpatched, expanding attack surface.[0]
  • Block and hunt for communications with the C2 IP 5.78.73.122 and review Black Lotus Labs' full C2 list.: Victims contact dedicated C2 servers to receive commands; Black Lotus Labs published all C2 IPs with first/last-seen dates.[0]
  • Monitor GPU/AI workload hosts for unexpected mining activity and outbound scanning behaviour.: PoeLLM deploys XMRig and Iron miners on compromised GPU hardware and turns victims into scanners and exploit servers.[0]
  • Treat innocuous-looking external content (e.g., poems/CSS files in public repos) as potential covert C2 channels in detection logic.: The malware encodes its C2 IP in an ordinary-looking GitHub poem with no links or files, defeating conventional malicious-content detection.[0]