Back to News
RSS feedwww.theregister.com

PoeLLM Malware Infects More Than 3,000 Servers Using Hidden Poem Commands

Summary

PoeLLM malware has infected more than 3,000 servers, mainly in the United States and Western Europe, since at least April 2026, with more than 800 active infections recorded at its peak. Black Lotus Labs attributes the financially motivated Canto Incognito campaign to an Italian-speaking criminal and says it is the first real-world case the researchers have observed of “adversarial poetry” being used to conceal an attack. The malware targets internet-facing, vulnerable AI-related services, especially LiteLLM and Ollama, while also reaching systems running Gotenberg and Gitea; a possible Ivanti Sentry compromise helped researchers identify the campaign. A poem posted in a GitHub repository contains phrases that the malware extracts and converts through a hard-coded dictionary into an IPv4 address for its current command-and-control server. Updating the poem can therefore redirect infected systems without an obvious link, file, or encrypted payload. PoeLLM deploys XMRig and Iron miners, connects victims to Kryptex, and uses compromised machines to scan for and exploit additional vulnerable systems. The researchers say the campaign demonstrates how expanding AI deployments can increase the exposed attack surface and expect similar attacks as more AI-enabled servers come online.