Lumen's Black Lotus Labs says the PoeLLM cryptomining botnet has compromised more than 2,100 servers, many running exposed LiteLLM or Ollama. Each host it takes then mines and scans for the next, so an AI server left open to the internet is attack surface to lock down.
Perspective Coverage
6 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence70
- Adoption50
- Hype gap+5
- Incentives
- Insufficient
- Confidence70
Justice says Chinese state operators laundered intrusions through infected routers and cameras in more than 130 countries since 2018. Source geography has been unreliable for years.
Perspective Coverage
7 publishers
- Builder
- Builder 32%
- Operator
- Operator 54%
- Investor
- Investor 14%
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+18
- Incentives58
- Confidence64
Black Lotus Labs counted about a dozen compromised enterprises, mostly in Asia and South America, on a framework that has been publishing operator commands to infected hosts through IoT message brokers since 2024.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 62%
- Investor
- Investor 11%
Reality
- Evidence66
- Adoption18
- Hype gap+20
- Incentives
- Insufficient
- Confidence64
The advisory puts Volt Typhoon inside communications, energy, transport and water IT environments across the US and Guam, and says the behaviour does not look like espionage. The planning problem is outage, not data loss.
Reality
- Evidence70
- Adoption58
- Hype gap+12
- Incentives55
- Confidence62
Black Lotus Labs assesses the botnet as Chinese state work under Flax Typhoon, assembled from SOHO routers, NVRs, NAS boxes and IP cameras whose 17-day average lifespan makes the infrastructure disposable by design.
Publishers:lumen.com
Reality
- Evidence58
- Adoption62
- Hype gap+15
- Incentives68
- Confidence57
Group-IB says the phishing kit Google sued over in June kept producing pages after the FBI seized its admin servers and wallets, which puts the durable detection signal in the kit's file names rather than its hosts.
Reality
- Evidence44
- Adoption66
- Hype gap+6
- Incentives58
- Confidence46
Black Lotus Labs counted about 650 JDY bots at the January 2024 low and more than 1,500 now, all of them fingerprinting exposed services soon after CVEs go public, with US military entities the most prominent target.
Publishers:lumen.com
Reality
- Evidence55
- Adoption50
- Hype gap+25
- Incentives70
- Confidence50
DOJ seized three domains on 26 August 2026 and disabled the QScan and QTRouter platforms. Both were sold as services to MSS and PLA customers, and the only telemetry that ever saw the traffic sat on the backbone.
Publishers:zerotracelab.com
Reality
- Evidence74
- Adoption71
- Hype gap+12
- Incentives62
- Confidence63
Black Lotus Labs spent a year mapping a service layer that hands reconnaissance, encrypted relays and routing to several Chinese state operators at the same time. IP-overlap attribution assumes that cannot happen.
Publishers:lumen.com
Reality
- Evidence45
- Adoption35
- Hype gap+28
- Incentives75
- Confidence45
Prosecutors say a Nanjing contractor rented IoT botnets and commercial proxies to the MSS and PLA from 2018. No individuals were charged, and the conscripted hardware stays conscripted.
Reality
- Evidence58
- Adoption47
- Hype gap+24
- Incentives62
- Confidence61
Lumen's Black Lotus Labs spent a year mapping a four-part framework sold to Chinese espionage operators. Its indicators belong to a supplier, so hunt the service rather than one group's habits.
Reality
- Evidence52
- Adoption58
- Hype gap+18
- Incentives66
- Confidence48