Lumen Black Lotus Labs
lumen-black-lotus-labs · B · candidate
https://www.lumen.com/en-us/security/black-lotus-labs.html
Added 2026-10-11: network-telemetry botnet and infrastructure research; the primary of the PoeLLM entry published this run (reported by BleepingComputer and The Register). No dated listing or working feed was verified (the blog.lumen.com tag feed does not parse); article pages sit under lumen.com/blog/en-us/<slug> and read with `extract`, and their metadata date can be wrong (2026-03-16 on a 2026-10-07 post). Reliability B until a track record exists.
Cited in 6 entries
Citation cadence
Citation days per ISO week (21 weeks of coverage span, total 5).
- PoeLLM: a cryptomining botnet that reads its C2 address out of a GitHub poem compromises exposed LiteLLM, Ollama, Gotenberg and Gitea servers and turns them into scanners2026-10-11
- BambooToken, a previously undocumented MQTT-based malware framework sideloads via a signed Chinese hardware-token utility to control Windows and Linux hosts2026-09-16
- DOJ/FBI seize domains behind QScan and QTRouter, the hacking-as-a-service platforms a PRC contractor sold to China's MSS and PLA, NASA, the Federal Reserve, DOJ, HHS, NIH and the US Senate named among the targets of QTFY, which DOJ separately dates to at least 2018; European infrastructure appears among Lumen's own profiled targets2026-08-28
- Black Lotus Labs: the Volt Typhoon-linked JDY botnet doubles to 1,500+ devices and weaponises CVE disclosures within hours2026-06-11
- Red Lamassu (Calypso/Bronze Medley): Showboat + JFMBackdoor telco espionage implant pair2026-05-22
- Calypso/Red Lamassu (Bronze Medley) deploys Showboat (Linux) and JFMBackdoor (Windows) against telecoms, new implant pair disclosed by Lumen Black Lotus Labs and PwC Threat Intelligence2026-05-22