Security News

Poem Hides Malware Instructions as PoeLLM Infects More Than 3,000 AI Servers

The Register · 8 Oct 2026
Key Takeaway Check whether any AI tools, document converters or development platforms in your business are exposed to the internet, and keep them patched or move them behind access controls.

Researchers at Lumen's Black Lotus Labs have tracked a malware family called PoeLLM that has infected more than 3,000 servers since April, mostly in the US and Western Europe. The attacker is financially motivated and is using the infected systems to mine cryptocurrency and to build a growing botnet. At its peak, the malware infected more than 800 active servers per day, and it continues to claim new victims.

The campaign, named Canto Incognito, hides its instructions in a poem posted to a GitHub repository. Researchers say this is the first real-world case they have seen of "adversarial poetry", a technique that turns harmful prompts into poems to trick AI models. The poem contains no links, files or encrypted text, so it looks harmless to anyone who finds it. Only someone with access to the malware would know it holds a hidden IP address.

Most victims were running vulnerable, internet-facing versions of open source AI tools LiteLLM and Ollama. Hundreds more were running Gotenberg, a PDF converter, and the software development platform Gitea. The attacker may also have targeted commercial software, including Ivanti Sentry. Researchers first found PoeLLM while investigating an Ivanti Sentry vulnerability, CVE-2026-10520. A compromised Ivanti Sentry victim contacted the attacker's server and soon began scanning for other vulnerable devices. Black Lotus Labs attributes the campaign to an Italian-speaking criminal.

PoeLLM AI security botnet cryptomining Ivanti
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Register, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.