Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
Poetry as a Cybersecurity Threat 🚨
A suspected Italian attacker armed with a malware-controlling poem has infected more than 3,000 servers since April, breaking into enterprise AI infrastructure to mine cryptocurrency and add compromised systems to its growing botnet. This is the first case of “adversarial poetry” - an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails.
Researchers from Lumen’s Black Lotus Labs, who have been tracking the PoeLLM malware, stated, “This is a first for us.” They explained that to anyone who comes across it, it appears simply as a poem on GitHub, lacking links, files to download, or encrypted text that could easily be flagged as malicious, even by advanced models.
Impact and Spread 🌍
PoeLLM malware has been active since at least April, primarily affecting servers located in the US and Western Europe. The malware abuses and scans for open-source AI systems and services. Most victims were running vulnerable, internet-facing versions of LiteLLM and Ollama. Additionally, hundreds of victims were using Gotenberg, a PDF converter, and the software development platform Gitea. The attacker may have also targeted commercial software, including Ivanti Sentry.
The threat hunters first spotted the PoeLLM malware while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. In early June 2026, a compromised Ivanti Sentry victim contacted a dedicated server at 5.78.73[REDACTED BY DNB EDITORS TO GET PAST GOOGLE FILTERS].
The Canto Incognito Campaign 🎭
Black Lotus Labs attributed the PoeLLM malware to an Italian-speaking criminal and named the financially motivated campaign Canto Incognito. This campaign hides malicious commands in a poem posted to a GitHub repository. Comments within the malware and on the attacker’s GitHub pages are in Italian, and netflow analyzed by Black Lotus Labs suggests that the attacker is located in Italy.
The malware deploys XMRig and Iron miners, connecting victims to Kryptex mining infrastructure. In addition to using compromised GPU hardware powering AI workloads to mine cryptocurrency, PoeLLM also turns victims’ machines into vulnerability scanners and exploit servers, allowing the attacker to compromise even more vulnerable systems. The malware finds its current command-and-control (C2) server from keywords in the poem, and when the operator changes the poem, the infected systems find the new C2 location by parsing the poem and extracting certain words and phrases.
Future Implications 🔮
The Canto Incognito campaign appears to be relatively unique in its targeting of multiple AI-related services. The collection of more than 3,000 PoeLLM victims exhibits multiple vulnerable services at any given time. Black Lotus Labs noted that the PoeLLM malware developer has been extremely successful in identifying vulnerable servers, deploying exploits, and conscripting victims to continue expanding the campaign. They expect to see more of these types of attacks in the near future, stating, “As more AI-enabled servers come online, malware like PoeLLM will continue to spread.”