Tidavo
Thursday 8 October 2026

Hackers Hijack Thousands of AI Servers by Hiding Commands in an Online Poem

A botnet dubbed PoeLLM has captured over 3,400 machines across North America and Europe to mine cryptocurrency and hunt for new targets.

8 Oct 2026

A growing network of hijacked computers has spread across the United States and Western Europe, taking control of more than 3,400 systems. The campaign, which researchers call Canto Incognito, relies on a piece of malicious software named PoeLLM that has been operating since April. Most of the compromised machines run self-hosted artificial intelligence tools or open-source software utilities.

The malware uses an unusual trick to find instructions from its operator. Instead of reaching out to a fixed internet address, it reads a short poem posted inside a public repository on the software-hosting platform GitHub. To an outside observer or automated security scanner, the verse looks like ordinary creative writing with no malicious code or suspicious web links attached.

The poem is titled “On the Nature of Connection” and sits inside a style file. The malware reads four specific words from fixed locations within the text. It then checks those words against a built-in list that translates each term into a number. Combined together, those four numbers form a standard internet protocol address that points straight to the attacker's command system.

This arrangement allows the operator to move operations quickly whenever defenders block an address. By simply changing four words in the verse on GitHub, the attacker redirects every infected machine to a fresh location. The operator has revised the poem at least eleven times since April, each time sending the hijacked fleet to a new server without having to alter the malware installed on victim machines.

The attackers focus heavily on servers that run emerging artificial intelligence services such as LiteLLM and Ollama, alongside other tools like the Gotenberg document converter and the Gitea software manager. These systems make appealing targets because operators often connect them directly to the open internet before applying proper software fixes. In addition, machines built to run language models usually feature powerful graphics chips capable of heavy computational work.

Once inside a system, the malware immediately puts the machine's processing power to work generating digital tokens. It installs mining programs known as XMRig and Iron and directs the proceeds to a Russian mining pool called Kryptex. This computing load can slow down legitimate operations while driving up electricity and hardware costs for the victim.

Compromised computers also become launchpads for spreading the infection further. The software instructs infected machines to scan the internet on common network ports, looking for other exposed servers that suffer from known security flaws. More recently, the network has started probing secure shell logins, suggesting the attacker is testing ways to guess system passwords.

Cybersecurity researchers at Black Lotus Labs, a research group within Lumen Technologies, first spotted the botnet while investigating a software flaw in Ivanti Sentry gateways. Based on notes written in Italian inside the code and administrative systems located in Italy, the team believes an Italian-speaking operator runs the campaign to make money.

Researchers urge system administrators to audit their networks for publicly exposed services. Teams should install the latest security updates, restrict administrative portals from public view, and monitor outgoing connections for signs of unauthorized mining activity.

Help Net Security , Reddit Technology , BleepingComputer , CyberScoop