‘This is news to us’: Attackers use poem to infect thousands of servers with malware
- A threat actor created malware that reads poems posted on GitHub
- The poems are a secret code for the location of the C2 servers.
- The servers instruct the malware to deploy cryptojackers and scanners.
Somewhere in the trackless wastes of cyberspace, a digital Robert Langdon is decoding an ancient poem to find the location of his masters and receive instructions on his next steps. I may be exaggerating a bit, but this is the gist of a rather strange story about cyberattacks and cryptocurrency mining.
Cybersecurity researchers at Lumen’s Black Lotus Labs found malware that obtains instructions about the location of the C2 server from a poem shared on GitHub.
By searching for specific words and decoding them into numbers, the malware can obtain an IP address where the C2 server is located and receive instructions on what to do next. Black Lotus calls it “adversarial poetry” and says he’s never seen anything like it.
Latest videos ofTechnologyRadar
adversary poetry
The attacker, who appears to be of Italian origin (or at least based in Italy), first searches for vulnerable Internet-connected services, such as LiteLLM or Ollama, and installs malware called PoeLLM.
This malware then goes to GitHub to search for a poem that appears to have been generated by AI. Here are the lines:
In the silent hum of the driver, the machines begin to speak,
Each diode pulse passes light through veins of copper.
We teach the darkness to carry meaning, byte by byte.
A language built from lightning, cold and clean.
Beyond the wall of encryption, a signal finds its way,
the ticking of distant servers responding.
Data moves like water through the cracks of ordered thought,
and somewhere in the code, the world stays the course.
He then looks up specific words in this poem: controller, diode, decryption, tick and compares them to the corresponding numbers (his dictionary is encrypted). When combined, they form an IPv4 address where the server is located.
PoeLLM then communicates with the server and receives instructions on what to do next. In most cases, it simply deploys a cryptocurrency miner called XMRig, which uses the device’s electrical power, computing, and Internet access to mine Monero tokens and enrich the malicious poet.
The malware can also run as a scanner, searching for additional vulnerable systems and allowing the attacker to break into even more devices.
changing the song
If the attacker needs to move the infrastructure, all they need to do is change certain words in the GitHub poem. Therefore, when infected machines retrieve the updated version, they can calculate the new C2 address without requiring a malware update. In fact, this has already happened several times.
According to The Register, the poem, titled “On the Nature of Connection,” has been updated 11 times since its initial publication. The last update occurred in September 2026.
“The Canto Incognito campaign appears to be relatively unique in its targeting of multiple AI-related services,” the researchers said. The Registry.
“Other notable campaigns this year, including the LiteLLM supply chain compromise, focused on a single service and affected approximately 2,500 victims, according to open sources. PoeLLM’s collection of more than 3,000 victims appears to exhibit multiple vulnerable services at any given time.”
In other words, the adversarial poetry campaign has been quite successful, infecting over 3,000 (confirmed) devices so far.
Malware developer PoeLLM “has been very successful in identifying vulnerable servers, deploying exploits, and recruiting victims to continue expanding the campaign,” Black Lotus Labs said.
“If the actor had only focused on one or two vulnerabilities, the pool of potential victims could have been quickly depleted, but the expanding scope allowed for a larger, more powerful (and more profitable) botnet.”
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment