The Broadband Guide
SG
search advanced

600,000 routers were bricked in a single cyberattack last year

2024-06-03 15:32 by

 

More than 600,000 small office/home office (SOHO) routers are estimated to have been bricked and taken offline following a destructive cyber attack staged by unidentified cyber actors, disrupting users' access to the internet.

Security analysts from Lumen Technologies' Black Lotus Labs detailed the attack in research published Thursday. All of the routers were leased by a single internet provider and were rendered permanently inoperable, requiring a hardware-based replacement. Nearly half of all the company's modems were abruptly taken offline over those three days in October.

While the researchers aren't identifying the ISP, the particulars they report match almost perfectly with those detailed in the October messages from Windstream subscribers. Specifically, the date the mass bricking started, the router models affected, the description of the ISP, and the displaying of a static red light by the out-of-commission ActionTec routers. Windstream representatives declined to answer questions sent by email.

Black Lotus Labs investigated based on repeated complaints across social media and outage detectors about specific routers, particularly the ActionTec T3200 and ActionTec T3260. Users reported their issues were resolved only by their provider replacing the affected devices.

The malicious firmware package that deleted parts of the operational code on impacted routers was identified as "Chalubo," a commodity remote access trojan. It's unclear how the firmware was shipped to customers - whether through an unknown exploit, weak credentials, or access to administrative tools - or who was behind the attack that the researchers called "a deliberate act intended to cause an outage."

"The event was unprecedented due to the number of units affected - no attack that we can recall has required the replacement of over 600,000 devices," Lumen's researchers wrote. "In addition, this type of attack has only ever happened once before, with AcidRain used as a precursor to an active military invasion."

Read more -here-

 

  Post your review/comments
    rate:
   avg:
News Glossary of Terms FAQs Polls Cool Links SpeedGuide Teams SG Premium Services SG Gear Store
Registry Tweaks Broadband Tools Downloads/Patches Broadband Hardware SG Ports Database Security Default Passwords User Stories
Broadband Routers Wireless Firewalls / VPNs Software Hardware User Reviews
Broadband Security Editorials General User Articles Quick Reference
Broadband Forums General Discussions
Advertising Awards Link to us Server Statistics Helping SG About