Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

PoeLLM malware infects over 3,000 servers using 'adversarial poetry'

A new malware campaign, Canto Incognito, has infected more than 3,000 servers since April by using a poem to hide malicious commands and bypass AI safety guardrails.

  • The PoeLLM malware, active since April, has infected over 3,000 servers, primarily in the US and Western Europe.
  • The malware uses 'adversarial poetry' to embed command-and-control server details within a poem on GitHub, tricking AI systems.
  • Black Lotus Labs attributes the campaign to an Italian-speaking individual, who uses compromised systems for cryptocurrency mining and to expand a botnet.

More than 3,000 servers have been infected since April by a new malware campaign known as PoeLLM, which uses a technique called “adversarial poetry” to bypass AI safety measures. The malware, tracked by Lumen’s Black Lotus Labs, is believed to be controlled by a suspected Italian attacker.

This marks the first real-world instance of adversarial poetry, where harmful prompts are disguised as poems to trick large language models (LLMs) into bypassing safety guardrails. The attacker hides malicious commands within a poem posted on a GitHub repository, which infected systems then parse to find new command-and-control (C2) server locations.

The Canto Incognito campaign, as named by Black Lotus Labs, primarily targets open-source AI systems and services, including vulnerable versions of LiteLLM and Ollama. Hundreds of victims were also running Gotenberg, a PDF converter, and the software development platform Gitea. The attacker may also have targeted commercial software such as Ivanti Sentry.

Compromised servers are used to mine cryptocurrency, specifically XMRig and Iron miners connected to Kryptex infrastructure. Additionally, the malware transforms victim machines into vulnerability scanners and exploit servers, enabling the attacker to compromise more systems and expand the botnet.

Why this matters: This campaign represents a new method of attack against AI infrastructure, demonstrating how malicious actors can use creative techniques like adversarial poetry to exploit vulnerabilities and bypass security measures.

What this means for you: If you use or manage internet-facing open-source AI systems like LiteLLM or Ollama, or software such as Gotenberg and Gitea, your systems could be vulnerable to similar attacks if not patched and protected.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.