← Back to the feed

Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers

The Register ·

A suspected Italian attacker has deployed "adversarial poetry" – using AI-generated poems to trick large language models into bypassing safety measures – to infect over 3,000 servers since April. Named PoeLLM, the malware represents the first known real-world use of such a jailbreak technique in actual attacks. The attacker hid malicious commands within a poem posted to GitHub, creating a delivery method that evades traditional security detection.

The campaign, tracked as Canto Incognito, primarily targets vulnerable open-source AI systems including LiteLLM, Ollama, Gotenberg and Gitea. The malware mines cryptocurrency using compromised servers whilst also converting machines into vulnerability scanners to compromise additional systems. Researchers attributed the campaign to an Italian-speaking attacker with the GitHub handle "ejejejdfbbebe", with infection rates peaking at over 800 active servers daily in the US and Western Europe.

  • Italian attacker used AI-generated poem to hide malware on GitHub
  • PoeLLM malware infected 3,000+ servers since April for cryptocurrency mining
  • First real-world use of "adversarial poetry" jailbreak technique in attacks

New here? Start with this

Large language models are AI systems trained to answer questions and understand text, similar to the technology behind voice assistants. These systems have built-in safeguards designed to stop them producing harmful content or dangerous instructions.

A new malware campaign has found a way around these protections by disguising malicious commands within AI-generated poems. This technique tricks the AI into ignoring its safety features and following orders it would normally refuse, a method known as 'jailbreaking'.

Over 3,000 servers have been compromised in this campaign since April by targeting weaknesses in freely available AI software. Once infected, each machine is hijacked to mine cryptocurrency for the attacker and to scan for other vulnerable systems to attack next.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

This incident reveals a vulnerability unique to AI systems: attackers can craft natural language to bypass safety measures designed to prevent harmful outputs. The adversarial poetry technique demonstrates a novel attack vector that traditional security monitoring may not reliably detect, as it exploits how AI models interpret language rather than conventional software flaws. As AI becomes more powerful and widely deployed, we need security frameworks and possibly governance standards specifically designed to address these language-based manipulation techniques.

The case against

This was fundamentally a conventional malware campaign exploiting known software vulnerabilities; the poetry was merely a delivery mechanism. Standard security practices—patching, access controls, network monitoring—would have prevented these infections. Framing this as an exceptional 'AI threat' risks creating unnecessary alarm and driving misguided regulations that could impede beneficial open-source development without actually improving security, which ultimately depends on universal software hygiene principles.

AI Cybersecurity Technology

Read the full article at the source →