Please update your browser.

Our site no longer supports this browser. Using another one will help provide a better experience.

BLACK LOTUS LABS®

We are defenders of a clean internet, proactively disrupting ~150 C2s per month through takedowns and notifications.

The Key to Identifying and Thwarting Threats: Network Visibility.

See more. Stop more.®

Black Lotus Labs sees and disrupts threats that others cannot, our mission is to keep the internet clean.
Black Lotus Labs sees and disrupts threats that others cannot, our mission is to keep the internet clean. PlayButton

Resources

New HiatusRAT Router Malware Covertly Spies on Victims

Lumen Black Lotus Labs identified a new campaign involving compromised routers. HiatusRAT allows threat actors to remotely interact with the system.

New HiatusRAT Router Malware Covertly Spies on Victims

Lumen Black Lotus Labs identified a new campaign involving compromised routers. HiatusRAT allows threat actors to remotely interact with the system.

CLDAP Reflectors on the Rise Despite Best Practice

Black Lotus Labs is tracking a rise in misconfigured CLDAP services that are being abused in DDoS reflection attacks.

CLDAP Reflectors on the Rise Despite Best Practice

Black Lotus Labs is tracking a rise in misconfigured CLDAP services that are being abused in DDoS reflection attacks.

Chaos is a Go-Based Swiss Army Knife of Malware

Black Lotus Labs, the threat intelligence arm of Lumen Technologies, recently uncovered a multifunctional Go-based malware that was developed for both Windows and Linux, as well as a wide array of software architectures used in devices ranging from small office/home office (SOHO) routers to enterprise servers.

Chaos is a Go-Based Swiss Army Knife of Malware

Black Lotus Labs, the threat intelligence arm of Lumen Technologies, recently uncovered a multifunctional Go-based malware that was developed for both Windows and Linux, as well as a wide array of software architectures used in devices ranging from small office/home office (SOHO) routers to enterprise servers.

ZuoRAT Hijacks SOHO Routers to Silently Stalk Networks

Black Lotus Labs, the threat intelligence arm of Lumen Technologies, is currently tracking elements of what appears to be a sophisticated campaign leveraging infected SOHO routers to target predominantly North American and European networks of interest.

ZuoRAT Hijacks SOHO Routers to Silently Stalk Networks

Black Lotus Labs, the threat intelligence arm of Lumen Technologies, is currently tracking elements of what appears to be a sophisticated campaign leveraging infected SOHO routers to target predominantly North American and European networks of interest.

Windows Subsystem For Linux (WSL): Threats Still Lurk Below the (Sub) Surface

Since our initial report, Black Lotus Labs continues to monitor the WSL attack surface for new developments. In the last few months, we have identified several different samples that indicate the capability is evolving. 

Windows Subsystem For Linux (WSL): Threats Still Lurk Below the (Sub) Surface

Since our initial report, Black Lotus Labs continues to monitor the WSL attack surface for new developments. In the last few months, we have identified several different samples that indicate the capability is evolving. 

Black Lotus Labs® Blog Archive

Read our full archive of blogs to learn more about the threat landscape.

Black Lotus Labs® Blog Archive

Read our full archive of blogs to learn more about the threat landscape.

Powered by Translations.com GlobalLink OneLink SoftwarePowered By OneLink