2026-10-11NOTABLELumen: a botnet takes its C2 address from a GitHub poem and spreads through exposed AI and developer servers
Gotenberg
product · product:gotenberg single-source
Coverage
1
first 2026-10-11 → last 2026-10-11
Latest activity
2026-10-11
Lumen: a botnet takes its C2 address from a GitHub poem and spreads through exposed AI and developer servers
Peak priority
notable
1 notable
Targets
technology
sectors: technology
Sources cited
2
2 hosts
Defender insights
What each entry about Gotenberg tells a defender to do, newest first.
Exposure · detection
Story timeline
ATT&CK techniques (6 across 5 tactics)
6 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissanceActive Scanning: Vulnerability Scanning
- Resource DevelopmentCompromise Infrastructure: Network Devices
- Initial AccessExploit Public-Facing Application
- Command and ControlWeb Service: Dead Drop Resolver · Ingress Tool Transfer
- ImpactResource Hijacking: Compute Hijacking
Reconnaissance TA0043
T1595.002Active Scanning: Vulnerability Scanning×1
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.
Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗
Resource Development TA0042
T1584.008Compromise Infrastructure: Network Devices×1
Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment, but rather to leverage these devices to support additional targeting.
Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗
Command and Control TA0011
T1102.001Web Service: Dead Drop Resolver×1
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗
Impact TA0040
T1496.001Resource Hijacking: Compute Hijacking×1
Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗
Entries about Gotenberg (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Gitea×1
- Ivanti Sentry×1
- LiteLLM×1
- Ollama×1
- PoeLLM×1
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (50%)
- lumen.com1 (50%)