600,000 routers were bricked in a single cyberattack last year2024-06-03 15:32 by Daniela
More than 600,000 small office/home office (SOHO) routers are estimated to have been bricked and taken offline following a destructive cyber attack staged by unidentified cyber actors, disrupting users' access to the internet. Security analysts from Lumen Technologies' Black Lotus Labs detailed the attack in research published Thursday. All of the routers were leased by a single internet provider and were rendered permanently inoperable, requiring a hardware-based replacement. Nearly half of all the company's modems were abruptly taken offline over those three days in October. While the researchers aren't identifying the ISP, the particulars they report match almost perfectly with those detailed in the October messages from Windstream subscribers. Specifically, the date the mass bricking started, the router models affected, the description of the ISP, and the displaying of a static red light by the out-of-commission ActionTec routers. Windstream representatives declined to answer questions sent by email. Black Lotus Labs investigated based on repeated complaints across social media and outage detectors about specific routers, particularly the ActionTec T3200 and ActionTec T3260. Users reported their issues were resolved only by their provider replacing the affected devices. The malicious firmware package that deleted parts of the operational code on impacted routers was identified as "Chalubo," a commodity remote access trojan. It's unclear how the firmware was shipped to customers - whether through an unknown exploit, weak credentials, or access to administrative tools - or who was behind the attack that the researchers called "a deliberate act intended to cause an outage." "The event was unprecedented due to the number of units affected - no attack that we can recall has required the replacement of over 600,000 devices," Lumen's researchers wrote. "In addition, this type of attack has only ever happened once before, with AcidRain used as a precursor to an active military invasion." Read more -here-
Post your review/comments
rate:
avg:
|