More than 3,000 servers have been infected since April by a new malware campaign known as PoeLLM, which uses a technique called “adversarial poetry” to bypass AI safety measures. The malware, tracked by Lumen’s Black Lotus Labs, is believed to be controlled by a suspected Italian attacker.
This marks the first real-world instance of adversarial poetry, where harmful prompts are disguised as poems to trick large language models (LLMs) into bypassing safety guardrails. The attacker hides malicious commands within a poem posted on a GitHub repository, which infected systems then parse to find new command-and-control (C2) server locations.
The Canto Incognito campaign, as named by Black Lotus Labs, primarily targets open-source AI systems and services, including vulnerable versions of LiteLLM and Ollama. Hundreds of victims were also running Gotenberg, a PDF converter, and the software development platform Gitea. The attacker may also have targeted commercial software such as Ivanti Sentry.
Compromised servers are used to mine cryptocurrency, specifically XMRig and Iron miners connected to Kryptex infrastructure. Additionally, the malware transforms victim machines into vulnerability scanners and exploit servers, enabling the attacker to compromise more systems and expand the botnet.