Mystery #malware destroys 600,000 #routers from a #Windstream's Kinetic #ISP during 72-hour span
Incident, "#PumpkinEclipse," believed to be result of deliberate attack using commodity malware, #Chalubo to overwrite #router #firmware. Windstream, which has about 1.6 million subscribers in 18 states, has not provided an explanation for outage. Company sent replacement routers to affected customers, many of whom reported significant financial losses due to the disruption.
https://arstechnica.com/security/2024/05/mystery-malware-destroys-600000-routers-from-a-single-isp-during-72-hour-span/
Mystery malware destroys 600,000 routers from a single ISP during 72-hour span

An unknown threat actor with equally unknown motives forces ISP to replace routers.

Ars Technica
Mysteriös: Malware zerstört Tausende Router pro Stunde | heise online
https://heise.de/-9742582 #Cybercrime #Malware #Chalubo #Router
Mysteriös: Malware zerstört Tausende Router pro Stunde

In nur 72 Stunden ging beim US-Provider Windstream die Hälfte aller Kunden offline. Hunderttausende Router mussten ausgetauscht werden. Der ISP schweigt.​

heise online

#Cybercriminals exploited the #Chalubo #trojan to launch an unprecedented destruction campaign, permanently disabling over 600,000 #internet routers within 72 hours.

https://gadgetbond.com/unknown-malware-destroys-600000-routers-in-72-hours/

Massive internet outage: 600,000 routers bricked in 3 days

An unidentified hacker bricked over 600,000 routers from a major ISP in just 72 hours using the Chalubo trojan, causing widespread internet outages.

GadgetBond
Mysteriös: Malware zerstört Tausende Router pro Stunde

In nur 72 Stunden ging beim US-Provider Windstream die Hälfte aller Kunden offline. Hunderttausende Router mussten ausgetauscht werden. Der ISP schweigt.​

heise online

Kit from #ActionTec and #Sagemcom remotely ruined and required replacement.

Almost half of #Windstream’s #Kinetic broadband users found their home routers completely dead, thanks to a malicious botnet known as #Chalubo. This happened seven months ago, but has only now come to light—via researchers who dubbed it #PumpkinEclipse.

It has echoes of Ukrainian #ISP modems mysteriously self destructing, just before the 2022 Russian invasion. In #SBBlogwatch, we wonder if this was a test of something bigger. At @TechstrongGroup’s @SecurityBlvd: https://securityboulevard.com/2024/05/pumpkin-eclipse-windstream-richixbw/?utm_source=richisoc&utm_medium=social&utm_content=richisoc&utm_campaign=richisoc

‘Pumpkin Eclipse’ — 600,000+ Rural ISP Routers Bricked Beyond Repair

Daft name, serious risk: Kit from ActionTec and Sagemcom remotely ruined and required replacement.

Security Boulevard
Over 600,000 SOHO routers were destroyed by Chalubo malware in 72 hours 

The Chalubo trojan destroyed over 600,000 SOHO routers from a single ISP, researchers from Lumen Technologies reported.

Security Affairs

#米国#プロバイダー の数十万台の #ルーター#破壊 された」: heiseonline

「10月末、米国のインターネットサービスプロバイダー #Windstream では数十万台のルーターがオフラインになった。 3 日以内に、顧客の約半数がインターネットにアクセスできなくなりました。 ルーターが突然役に立たなくなり、交換する必要がありました。 リセットは機能しませんでした。 この #ISP は、米国 18 州、主に農村部の 120 万世帯未満と数万の企業にサービスを提供しています。 セキュリティ研究者のルーメンス氏によると、原因はルータの #ファームウェア への悪意のあるアップデートで、「 #Chalubo 」と呼ばれる #マルウェア が注入されたものだという。 」

https://www.heise.de/news/Hunderttausende-Router-eines-US-Providers-zerstoert-9742582.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#prattohome #heiseonline

Mysteriös: Malware zerstört Tausende Router pro Stunde

In nur 72 Stunden ging beim US-Provider Windstream die Hälfte aller Kunden offline. Hunderttausende Router mussten ausgetauscht werden. Der ISP schweigt.​

heise online
Hackers Actively Exploited 0-Day in CCTV Camera Hardware

Criminals behind botnets Chalubo, FBot and Moobot attack unpatched vulnerabilities in the commercial DVRs made by LILIN.

Threatpost - English - Global - threatpost.com