Home TechnologyHackers Use AI-Generated Poem to Control Thousands of Infected Servers

Hackers Use AI-Generated Poem to Control Thousands of Infected Servers

by Phoenix 24

The most dangerous code may no longer look like code.

United States

Cybersecurity researchers have uncovered an unusual malware campaign in which attackers use an apparently harmless AI-generated poem to conceal and update the location of their command-and-control infrastructure. The operation, known as Canto Incognito, has compromised more than 3,000 servers and demonstrates how cybercriminals are beginning to combine artificial intelligence infrastructure with creative methods of evading conventional detection.

The malware, called PoeLLM, targets exposed services associated with artificial intelligence, including LiteLLM and Ollama. Once a vulnerable server is compromised, the malicious software searches for a poem stored in a public repository. Certain words inside the text act as hidden instructions, allowing the malware to calculate the internet address of the server controlling the operation.

The technique is striking because the poem itself does not contain an obvious malicious command. Specific words are translated into numerical values through a dictionary already embedded inside the malware. Those values are then combined to reconstruct the address of the command-and-control server. By changing only a few words in the poem, attackers can redirect thousands of infected machines without distributing a new version of the malware.

Researchers say the text has already been modified multiple times, illustrating the flexibility of the method. Once PoeLLM reaches its control infrastructure, it commonly downloads cryptocurrency-mining software that uses the victim’s electricity, computing power and internet connection to generate Monero for the attackers. Infected machines can also search for additional vulnerable servers, allowing the botnet to expand autonomously.

The campaign is especially relevant because it targets infrastructure built around artificial intelligence. Organizations are rapidly deploying open-source AI services, but systems exposed directly to the internet can become attractive targets when vulnerabilities remain unpatched. The same computing resources that make AI servers valuable for legitimate applications also make them profitable platforms for cryptocurrency mining and other malicious activity.

The larger cybersecurity implication is significant. Defensive systems have traditionally searched for suspicious files, malicious domains or recognizable command structures. Canto Incognito demonstrates that ordinary text can become part of malware infrastructure when software is programmed to interpret selected words as operational data.

This creates a new challenge for security teams. Cyber threats are increasingly moving beyond recognizable malicious code toward combinations of legitimate platforms, public content and hidden machine-readable signals. The distinction between harmless information and executable infrastructure is becoming less obvious.

The next generation of cyberattacks may hide not behind encrypted code, but inside content designed to look completely ordinary.

You may also like