Security News > 2024 > May > Malware botnet bricked 600,000 routers in mysterious 2023 attack
![Malware botnet bricked 600,000 routers in mysterious 2023 attack](/static/build/img/news/malware-botnet-bricked-600000-routers-in-mysterious-2023-attack-medium.jpg)
A malware botnet named 'Pumpkin Eclipse' performed a mysterious destructive event in 2023 that destroyed 600,000 office/home office internet routers offline, disrupting customers' internet access.
The incident had a focused impact, affecting a single internet service provider and three models of routers used by the firm: the ActionTec T3200s, ActionTec T3260s, and Sagemcom F5380.
Starting on October 25, 2023, Windstream customers began reporting on Reddit that their routers were no longer working.
Fast forward seven months and a new report by Black Lotus may finally shed some light on the incident, explaining that a botnet was responsible for bricking 600,000 routers across the midwest states at a single ISP in October 2023.
Only one of these panels was used for the destructive attack and it focused on a specific American ISP, causing Black Lotus researchers to believe that the attacker purchased the Chalubo panel for the specific purpose of deploying the destructive payload on routers.
New Cuttlefish malware infects routers to monitor traffic for credentials.
News URL
Related news
- Malware botnet bricked 600,000 routers in mysterious 2023 event (source)
- New Latrodectus malware attacks use Microsoft, Cloudflare themes (source)
- New Cuttlefish malware infects routers to monitor traffic for credentials (source)
- New Cuttlefish Malware Hijacks Router Connections, Sniffs for Cloud Credentials (source)
- New "Goldoon" Botnet Targets D-Link Routers With Decade-Old Flaw (source)
- New SOHO router malware aims for cloud accounts, internal company resources (source)
- Finland warns of Android malware attacks breaching bank accounts (source)
- Ebury botnet malware infected 400,000 Linux servers since 2009 (source)
- Microsoft fixes Windows zero-day exploited in QakBot malware attacks (source)
- Ebury Botnet Malware Compromises 400,000 Linux Servers Over Past 14 Years (source)