Urgent.News

What's breaking now, across thousands of outlets.

Tech

'This is a first for us': Attackers uses poem to infect thousands of servers with malware

A malware hunts for hidden messages in poems posted on GitHub.

'This is a first for us': Attackers uses poem to infect thousands of servers with malware

A bizarre cyberattack has emerged, with attackers employing a poem posted on GitHub to infect thousands of servers with malware. This "adversarial poetry" campaign, discovered by cybersecurity researchers at Lumen’s Black Lotus Labs, demonstrates a unique method of transmitting commands to infected machines.

The attacker, believed to be of Italian origin, targets vulnerable internet-facing services, such as LiteLLM or Ollama, and installs malware known as PoeLLM. This malware searches GitHub for an AI-generated poem that serves as a secret code for the location of command and control (C2) servers. The C2 servers instruct the malware to deploy cryptojackers and scanners.

Within the poem, the attacker identifies specific words, like "driver," "diode," "decryption," "tick," and matches them to corresponding numbers using a hardcoded dictionary. When these numbers are combined, they reveal an IPv4 address where the C2 server is located. PoeLLM then connects to the server and receives further instructions on what actions to perform.

Most often, the malware simply installs a cryptocurrency miner called XMRig, utilizing the infected device's electricity, computing power, and internet connection to mine Monero tokens and benefit the malicious actor. In some instances, the malware operates as a scanner, searching for additional vulnerable systems and allowing the attacker to infiltrate more devices.

The attackers can change words in the GitHub poem to update the C2 address without needing a malware update. This tactic has been employed multiple times, with the poem "On the Nature of Connection" being updated 11 times since its initial commit. The most recent update occurred in September 2026.

The Black Lotus Labs researchers describe this campaign as relatively unique due to its targeting of multiple AI-related services. Other campaigns this year, such as the LiteLLM supply chain compromise, focused on a single service and affected around 2,500 victims. However, the adversarial poetry campaign has been successful, infecting more than 3,000 confirmed devices.

The malware developer has demonstrated proficiency in identifying vulnerable servers, deploying exploits, and expanding the campaign to a larger, more profitable botnet.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Thursday 8 October →