Lumen’s threat intelligence team, Black Lotus Labs, published new research on a campaign that breaks into exposed enterprise AI tools and uses their powerful hardware (i.e., data center GPUs) to mine cryptocurrency.
The campaign is proof of an attack tested in research: adversarial poetry. In this campaign, the attacker controls a malware campaign with poetry.
To steer infected machines, the attacker posted a poem on GitHub. The malware pulls out four specific words, converts each into a number, and gets the address of the attacker’s control server. When that server is blocked, the attacker simply edits the poem. It has been rewritten 11 times since April.
Quick details:
- Who was hit: More than 2,000 servers, mostly in the U.S. and Western Europe.
- Hijacked infrastructure: The attacker rented no servers. They used hijacked home and office routers instead.
- Victims become recruiters: Each infected server scans the internet for the next victim.
Why it matters: Behind the quirky method is a trend. AI systems are now a target in their own right. Compounding this, companies are putting AI tools online faster than they’re securing them. This attacker is profiting from that gap and is already testing new ways to break into more systems.
Read more here: https://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malware
Lumen Black Lotus Labs: Attacker running malware with a poemÂ
Posted in Commentary with tags Lumen on October 7, 2026 by itnerdLumen’s threat intelligence team, Black Lotus Labs, published new research on a campaign that breaks into exposed enterprise AI tools and uses their powerful hardware (i.e., data center GPUs) to mine cryptocurrency.
The campaign is proof of an attack tested in research: adversarial poetry. In this campaign, the attacker controls a malware campaign with poetry.
To steer infected machines, the attacker posted a poem on GitHub. The malware pulls out four specific words, converts each into a number, and gets the address of the attacker’s control server. When that server is blocked, the attacker simply edits the poem. It has been rewritten 11 times since April.
Quick details:
Why it matters: Behind the quirky method is a trend. AI systems are now a target in their own right. Compounding this, companies are putting AI tools online faster than they’re securing them. This attacker is profiting from that gap and is already testing new ways to break into more systems.
Read more here: https://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malware
Leave a comment »