Hackers came up with “malicious poetry” – poems on GitHub help control the virus and infect new computers Hackers came up with “malicious poetry” – poems on GitHub help control the virus and infect new computers

Hackers came up with “malicious poetry” – poems on GitHub help control the virus and infect new computers

Hackers hid the address of the command server for the virus in a poem. The malware discovered by researchers reads a text in verse published on GitHub, uses keywords to calculate the IP address of the C2 control server, and then mines the Monero cryptocurrency on infected systems and scans the Internet in search of new victims.

Hackers came up with “malicious poetry” – poems on GitHub help control the virus and infect new computers

Image source: Andras Vas / unsplash.com

The discovery was made by specialists from Black Lotus Labs (part of Lumen). The program finds certain words in the text and converts them into numbers – this is how it determines the IP address of the C2 server and receives instructions for action. Experts called this method “harmful poetry” and admitted that they had never encountered anything like this before.

The attacker operates from Italy. It looks for vulnerable Internet services, such as LiteLLM or Ollama, and installs the PoeLLM malware on them. She turns to GitHub in search of a poem that is believed to have been created by artificial intelligence. Researchers give an example of such a work:

“In the quiet hum of the car drivers begin to speak,
Each pulse of the diode penetrates the copper conductors with light.
We taught the darkness to carry meaning, byte by byte –
The lightning-woven tongue is cold and pure.
Behind the encryption wall the signal finds its way,
Distant servers tick in response.
Data flows like water through the cracks of ordered thought,
And somewhere in the code the world continues its course.”

  Image source: Boitumelo / unsplash.com

Image source: Boitumelo / unsplash.com

The program searches for keywords in the poem and matches them with numbers – the dictionary is built into its code, and when combined, these numbers form the IPv4 address of the server. PoeLLM contacts him and receives instructions on further actions. In most cases, the program deploys the XMRig cryptocurrency miner to mine Monero tokens. The malware can also operate in scanner mode, looking for vulnerable systems and allowing the attacker to penetrate new machines.

If an attacker needs to change the infrastructure, all they need to do is change a few words in a poem on GitHub. Infected machines will calculate the new address of the control server, and the malicious code itself will not need to be changed. This has already happened several times in practice: since the first publication, the poem has been updated 11 times; the last update dates back to September 2026.

“The Canto Incognito campaign is unique because it targets multiple AI-related services. Other notable campaigns this year, including the LiteLLM supply chain attack, targeted a single service and affected approximately 2,500 victims, according to public sources. In the case of PoeLLM, the number of victims exceeds 3000, and the attack affects several vulnerable services at once. If an attacker had limited himself to just one or two vulnerabilities, the pool of potential victims could have quickly become exhausted, and expanding his reach would allow the creation of a larger, more powerful (and profitable) botnet.”said the researchers.

If you notice an error, select it with the mouse and press CTRL+ENTER.

Leave a Reply

Your email address will not be published. Required fields are marked *