logo

Malware botnet bricked 600,000 routers in mysterious 2023 attack

ID: 2a17f9dd-1aea-59b4-9747-95d8785c2319

STIX ID: report--2a17f9dd-1aea-59b4-9747-95d8785c2319

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2024-05-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Black Lotus Labs reports a destructive botnet campaign nicknamed 'Pumpkin Eclipse' that, between October 25–27, 2023, rendered approximately 600,000 SOHO routers permanently inoperable at a single U.S. ISP by deploying the Chalubo malware: an in-memory MIPS binary using ChaCha20-encrypted C2, Lua-based command modules, and destructive payloads that forced hardware replacement and caused a 49% modem loss across the provider's ASN.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.