CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Gotenberg

product · product:gotenberg single-source

Coverage
1
first 2026-10-11 → last 2026-10-11
Latest activity
2026-10-11
Lumen: a botnet takes its C2 address from a GitHub poem and spreads through exposed AI and developer servers
Peak priority
notable
1 notable
Targets
technology
sectors: technology
Sources cited
2
2 hosts

Defender insights

What each entry about Gotenberg tells a defender to do, newest first.

2026-10-11NOTABLELumen: a botnet takes its C2 address from a GitHub poem and spreads through exposed AI and developer servers

Exposure · detection

Story timeline

  1. 2026-10-11PoeLLM: a cryptomining botnet that reads its C2 address out of a GitHub poem compromises exposed LiteLLM, Ollama, Gotenberg and Gitea servers and turns them into scanners
    active-threatsLumen: a botnet takes its C2 address from a GitHub poem and spreads through exposed AI and developer servers

Hunting pivots

Releases covered
Gotenberg
ATT&CK techniques (6 across 5 tactics)

6 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ReconnaissanceActive Scanning: Vulnerability Scanning
  • Resource DevelopmentCompromise Infrastructure: Network Devices
  • Initial AccessExploit Public-Facing Application
  • Command and ControlWeb Service: Dead Drop Resolver · Ingress Tool Transfer
  • ImpactResource Hijacking: Compute Hijacking

Reconnaissance TA0043

T1595.002Active Scanning: Vulnerability Scanning×1

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗

Resource Development TA0042

T1584.008Compromise Infrastructure: Network Devices×1

Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment, but rather to leverage these devices to support additional targeting.

Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗

Command and Control TA0011

T1102.001Web Service: Dead Drop Resolver×1

Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.

Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗

Impact TA0040

T1496.001Resource Hijacking: Compute Hijacking×1

Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Evidence: 2026-10-11/poellm-botnet-github-poem-c2-exposed-ai-and-gitea-servers · ATT&CK page ↗

Entries about Gotenberg (1)

2026-10-11 · view entry permalink →

NOTABLENATOB2

PoeLLM: a cryptomining botnet that reads its C2 address out of a GitHub poem compromises exposed LiteLLM, Ollama, Gotenberg and Gitea servers and turns them into scanners

Lumen's Black Lotus Labs says PoeLLM has been active since at least April 2026, deploys XMRig and Iron cryptocurrency miners that connect to a Kryptex mining pool, and is deployed through vulnerability exploitation of publicly exposed services, mainly LiteLLM and Ollama and, in the hundreds, the Gotenberg PDF converter and Gitea, with other products such as Ivanti Sentry possibly targeted (Lumen, 2026-10-07). It counts more than 3,400 impacted servers, a figure it raised after first circulating the report (BleepingComputer, 2026-10-07), predominantly in the United States and Western Europe, and assesses that PoeLLM is associated with an Italian-speaking threat actor (Lumen, 2026-10-07).

The command channel is the unusual part: the malware derives its current C2 server from keywords in a poem hosted in a GitHub repository, so the operator rotates servers by editing the poem, which Lumen counts 11 edits of since the first commit on 2026-04-13 (Lumen, 2026-10-07). Several C2 servers were routers with exposed administration pages, which Lumen reads as the operator repurposing compromised routers (Lumen, 2026-10-07). Infected servers become scanners and exploit launchers that sweep ports 3000 and 4000, the primary ports of Gotenberg and LiteLLM, and send a crafted POST that makes the target fetch a payload from the C2; the payload is a single ELF binary that bundles a remote shell, the miners, HTTP and HTTPS scanning and exploit deployment, and beacons back to the C2 (Lumen, 2026-10-07). For LiteLLM, Lumen says the endpoint /mcp-rest/test/connection, which the CVE-2026-42271 command injection references, was likely the exploitation path (Lumen, 2026-10-07), and BleepingComputer adds that Horizon3 showed it can be chained with CVE-2026-48710 for unauthenticated remote code execution (BleepingComputer, 2026-10-07). Lumen met the infrastructure while investigating the Ivanti Sentry flaw CVE-2026-10520, when a compromised Sentry victim contacted a PoeLLM C2 and began scanning for other vulnerable devices; it states no further link between that flaw and the botnet (Lumen, 2026-10-07).

The malware derives its current C2 server from keywords in a poem hosted in a GitHub repository.

We assess that PoeLLM is associated with an Italian-speaking threat actor and is deployed through vulnerability exploitation of publicly exposed services.

Lumen Black Lotus Labs 2026-10-07

Builds on: CVE-2026-42271, BerriAI LiteLLM: low-privilege command injection to host RCE, added to CISA KEV · CVE-2026-48710 "BadHost", Starlette (FastAPI / vLLM / LiteLLM / MCP SDK): Pre-Auth Auth Bypass… · Three unrelated AI platforms, three intrusions, one pattern: gateways and orchestrators… · CVE-2026-10520 / CVE-2026-10523, Ivanti Sentry: pre-auth OS command injection to root (CVSS…

threat11 Oct 03:37Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • bleepingcomputer.com1 (50%)
  • lumen.com1 (50%)