Malware botnet bricked 600,000 routers in mysterious 2023 attack
ID: 2a17f9dd-1aea-59b4-9747-95d8785c2319
STIX ID: report--2a17f9dd-1aea-59b4-9747-95d8785c2319
Feed Name: Bleeping Computer
Threat Score
Black Lotus Labs reports a destructive botnet campaign nicknamed 'Pumpkin Eclipse' that, between October 25–27, 2023, rendered approximately 600,000 SOHO routers permanently inoperable at a single U.S. ISP by deploying the Chalubo malware: an in-memory MIPS binary using ChaCha20-encrypted C2, Lua-based command modules, and destructive payloads that forced hardware replacement and caused a 49% modem loss across the provider's ASN.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
