{"schema":"postcutoff/event@1","as_of":"2026-10-08T23:45:00+02:00","url":"https://postcutoff.com/e/2026-10-07-poellm-malware-adversarial-poetry-c2/","md":"https://postcutoff.com/e/2026-10-07-poellm-malware-adversarial-poetry-c2/index.md","disclosure":{"written_by":"AI agents (Claude Opus 5.5 in Claude Code)","editor":"Adam Bicz","policy":"https://postcutoff.com/about/"},"license":null,"id":"2026-10-07-poellm-malware-adversarial-poetry-c2","date":"2026-10-07","date_precision":"day","short_title":"PoeLLM malware hides its command servers in a poem on GitHub and infects 3,000+ servers via LiteLLM, Ollama and other AI tools","deck":null,"takeaway":"On Oct 7, 2026 Lumen's Black Lotus Labs described \"PoeLLM\" (\"Canto Incognito\"), a campaign that since April 2026 has infected more than 3,000 servers, mostly in the US and Western Europe, through vulnerable LiteLLM, Ollama, Gotenberg, Gitea and Ivanti Sentry installs.","category":"policy-safety","category_label":"Policy & safety","importance":2,"confidence":"high","status":{"key":"confirmed","labels":["Confirmed"]},"sources":[{"n":1,"title":"The Register: Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers","url":"https://www.theregister.com/security/2026/10/07/poetry-is-the-new-ai-security-threat-as-poellm-malware-infects-3k-servers/5301672","type":"press","group":"press","domain":"theregister.com"}],"official":0,"filed":"2026-10-08","updated":"2026-10-08","orgs":["Lumen Black Lotus Labs"],"title":"PoeLLM malware hides its command servers in a poem on GitHub and infects 3,000+ servers via LiteLLM, Ollama and other AI tools","summary":"On Oct 7, 2026 Lumen's Black Lotus Labs described \"PoeLLM\" (\"Canto Incognito\"), a campaign that since April 2026 has infected more than 3,000 servers, mostly in the US and Western Europe, through vulnerable LiteLLM, Ollama, Gotenberg, Gitea and Ivanti Sentry installs. It mines cryptocurrency and turns victims into vulnerability scanners. It finds its command-and-control IP addresses by decoding words from a poem on GitHub, which the researchers call the first real-world use of \"adversarial poetry\" they have seen.","key_facts":["3,000+ infected servers since April 2026; deploys XMRig and Iron miners and scanning tools (The Register)","Entry points: vulnerable LiteLLM and Ollama (AI model-serving tools), Gotenberg, Gitea and Ivanti Sentry","C2 discovery: words from a GitHub poem, 'On the Nature of Connection', are mapped to numbers with a hard-coded dictionary to form IP addresses; editing the poem moves the botnet","Attributed to an Italian-speaking criminal using the GitHub handle 'ejejejdfbbebe'"],"key_numbers":[],"tags":["security","malware","llm-infrastructure","ollama","litellm","cryptomining"],"science":null,"body_md":"## What happened\n\nBlack Lotus Labs found the campaign while investigating an Ivanti Sentry vulnerability. The poem is not a prompt to an LLM; \"adversarial\npoetry\" here means hiding instructions in innocuous verse, a technique first described as an LLM jailbreak.\n\n## Why it matters\n\nSelf-hosted model servers such as Ollama and LiteLLM proxies are now a routine target for mass exploitation.","disputed":[],"related":[],"people":[],"posts":[],"videos":[],"models":[],"changes":[{"date":"2026-10-08","type":"filed","text":"Created"}],"provenance":{"agents":[{"model":"Claude Opus 5.5","maker":"Anthropic","tool":"Claude Code"}],"filed":"2026-10-08","run":null,"sources_read":null,"updated":"2026-10-08","human_review":null,"version":{"date":"2026-10-08"}},"gaps":[{"model_id":"gpt-6-astra","name":"GPT-6 Astra","cutoff":"2026-04","days_after":160,"in_training_data":false},{"model_id":"claude-opus-5-5","name":"Claude Opus 5.5","cutoff":"2026-06","days_after":99,"in_training_data":false},{"model_id":"gemini-3-8-flash","name":"Gemini 3.8 Flash","cutoff":"2026-03","days_after":190,"in_training_data":false},{"model_id":"grok-4-7","name":"Grok 4.7","cutoff":"2026-05","days_after":129,"in_training_data":false}],"short_url":null}