Mystery miscreant remotely bricked 600,000 SOHO routers with malicious firmware update
ID: 2089a185-6a66-55cb-9916-e88b91674609
STIX ID: report--2089a185-6a66-55cb-9916-e88b91674609
Feed Name: The Register (Security)
Threat Score
Security researchers at Lumen's Black Lotus Labs reported a large-scale destructive incident dubbed “Pumpkin Eclipse” in which unknown attackers used the Chalubo RAT to deliver a malicious firmware update that permanently disabled over 600,000 ActionTec T3200/T3260 routers within a single ASN over a 72-hour period in October 2023; the attack required hardware replacement for affected devices and has no confirmed nation-state attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
