PUMPKIN ECLIPSE — Mystery malware destroys 600,000 routers from a single ISP during 72-hour span An unknown threat actor with equally unknown motives forces ISP to replace routers.
Dan Goodin – May 30, 2024 2:00 pm UTC EnlargeGetty Images reader comments 0
One day last October, subscribers to an ISP known as Windstream began flooding message boards with reports their routers had suddenly stopped working and remained unresponsive to reboots and all other attempts to revive them.
The routers now just sit there with a steady red light on the front, one user wrote, referring to the ActionTec T3200 router models Windstream provided to both them and a next door neighbor. They won’t even respond to a RESET.
In the messageswhich appeared over a few days beginning on October 25many Windstream users blamed the ISP for the mass bricking. They said it was the result of the company pushing updates that poisoned the devices. Windstreams Kinetic broadband service has about 1.6 million subscribers in 18 states, including Iowa, Alabama, Arkansas, Georgia, and Kentucky. For many customers, Kinetic provides an essential link to the outside world.
We have 3 kids and both work from home, another subscriber wrote in the same forum. This has easily cost us $1,500+ in lost business, no tv, WiFi, hours on the phone, etc. So sad that a company can treat customers like this and not care.
After eventually determining that the routers were permanently unusable, Windstream sent new routers to affected customers. Black Lotus has named the event Pumpkin Eclipse. A deliberate act
A report published Thursday by security firm Lumen Technologies Black Lotus Labs may shed new light on the incident, which Windstream has yet to explain. Black Lotus Labs researchers said that over a 72-hour period beginning on October 25, malware took out more than 600,000 routers connected to a single autonomous system number belonging to an unnamed ISP.
While the researchers arent identifying the ISP, the particulars they report match almost perfectly with those detailed in the October messages from Windstream subscribers. Specifically, the date the mass bricking started, the router models affected, the description of the ISP, and the displaying of a static red light by the out-of-commission ActionTec routers. Windstream representatives declined to answer questions sent by email.
According to Black Lotus, the routersconservatively estimated at a minimum of 600,000were taken out by an unknown threat actor with equally unknown motivations. The actor took deliberate steps to cover their tracks by using commodity malware known as Chalubo, rather than a custom-developed toolkit. A feature built into Chalubo allowed the actor to execute custom Lua scripts on the infected devices. The researchers believe the malware downloaded and ran code that permanently overwrote the router firmware. Advertisement
We assess with high confidence that the malicious firmware update was a deliberate act intended to cause an outage, and though we expected to see a number of router make and models affected across the internet, this event was confined to the single ASN, Thursdays report stated before going on to note the troubling implications of a single piece of malware suddenly severing the connections of 600,000 routers.
The researchers wrote:
Destructive attacks of this nature are highly concerning, especially so in this case. A sizeable portion of this ISPs service area covers rural or underserved communities; places where residents may have lost access to emergency services, farming concerns may have lost critical information from remote monitoring of crops during the harvest, and health care providers cut off from telehealth or patients records. Needless to say, recovery from any supply chain disruption takes longer in isolated or vulnerable communities.
After learning of the mass router outage, Black Lotus began querying the Censys search engine for the affected router models. A one-week snapshot soon revealed that one specific ASN experienced a 49 percent drop in those models just as the reports began. This amounted to the disconnection of at least 179,000 ActionTec routers and more than 480,000 routers sold by Sagemcom. EnlargeBlack Lotus Labs
The constant connecting and disconnecting of routers to any ISP complicates the tracking process, because its impossible to know if a disappearance is the result of the normal churn or something more complicated. Black Lotus said that a conservative estimate is that at least 600,000 of the disconnections it tracked were the result of Chaluba infecting the devices and, from there, permanently wiping the firmware they ran on.
After identifying the ASN, Black Lotus discovered a complex multi-path infection mechanism for installing Chaluba on the routers. The following graphic provides a logical overview. EnlargeBlack Lotus Labs
Further ReadingMystery solved in destructive attack that knocked out >10k Viasat modemsThere aren’t many known precedents for malware that wipes routers en masse in the way witnessed by the researchers. Perhaps the closest was the discovery in 2022 of AcidRain, the name given to malware that knocked out 10,000 modems for satellite Internet provider Viasat. The outage, hitting Ukraine and other parts of Europe, was timed to Russia’s invasion of the smaller neighboring country.
A Black Lotus representative said in an interview that researchers can’t rule out that a nation-state is behind the router-wiping incident affecting the ISP. But so far, the researchers say they aren’t aware of any overlap between the attacks and any known nation-state groups they track. Advertisement
The researchers have yet to determine the initial means of infecting the routers. It’s possible the threat actors exploited a vulnerability, although the researchers said they aren’t aware of any known vulnerabilities in the affected routers. Other possibilities are the threat actor abused weak credentials or accessed an exposed administrative panel. An attack unlike any other
While the researchers have analyzed attacks on home and small office routers before, they said two things make this latest one stand out. They explained:
First, this campaign resulted in a hardware-based replacement of the affected devices, which likely indicates that the attacker corrupted the firmware on specific models. The event was unprecedented due to the number of units affectedno attack that we can recall has required the replacement of over 600,000 devices. In addition, this type of attack has only ever happened once before, with AcidRain used as a precursor to an active military invasion.
They continued:
The second unique aspect is that this campaign was confined to a particular ASN. Most previous campaigns weve seen target a specific router model or common vulnerability and have effects across multiple providers networks. In this instance, we observed that both Sagemcom and ActionTec devices were impacted at the same time, both within the same providers network.This led us to assess it was not the result of a faulty firmware update by a single manufacturer, which would normally be confined to one device model or models from a given company. Our analysis of the Censys data shows the impact was only for the two in question. This combination of factors led us to conclude the event was likely a deliberate action taken by an unattributed malicious cyber actor, even if we were not able to recover the destructive module.
With no clear idea how the routers came to be infected, the researchers can only offer the usual generic advice for keeping such devices free of malware. That includes installing security updates, replacing default passwords with strong ones, and regular rebooting. ISPs and other organizations that manage routers should follow additional advice for securing the management interfaces or administering the devices.
Thursday’s report includes IP addresses, domain names, and other indicators that people can use to determine if their devices have been targeted or compromised in the attacks. reader comments 0 Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Related Stories Today on Ars
Tesla (TSLA) is soaring in anticipation that Trump’s administration will make an easier path for Tesla’s self-driving tech, which still doesn’t work, to be approved federally.
Currently, self-driving technology is addressed at the state level, with each state having its own regulations for approving self-driving systems on its roads.
During a conference call following Tesla’s last earnings results, CEO Elon Musk, who has been financially backing the reelection of Donald Trump and “fully endorsed” him, hinted that he could work with the new federal government to get a federal self-driving approval process going.
Now, Bloomberg reports that Trump’s transition team is discussing making it a priority:
Members of President-elect Donald Trump’s transition team have told advisers they plan to make a federal framework for fully self-driving vehicles one of the Transportation Department’s priorities, according to people familiar with the matter.
This news sent Tesla’s stock up 7%, or an increase of 470 billion in value.
That’s surprising because before now, the regulatory aspect of Tesla’s self-driving effort didn’t seem like the biggest hurdle – making the technology work still seems to be the biggest hurdle.
Tesla has been wrong about its self-driving timeline too many times to count, but the latest one is to release unsupervised self-driving in California and Texas in Q2 2025.
Tesla has not released any data about its self-driving effort, and therefore, the best data available is crowdsourced. That data currently shows about 241 miles between critical disengagement:
Tesla would need a 2,500x improvement in miles between disengagement to reach a safer-than-human level, which has been the goal before getting regulatory approval.
Electrek’s Take
That sounds like a much bigger hurdle than getting regulatory approval.
I actually agree with the Trump administration that it makes more sense to have a federal framework for approving self-driving systems than at the state level.
But I don’t see how it will help Tesla since there’s no clear path to Tesla achieving a level safer than human with their current approach any time soon.
At the current pace, the 2,500x improvement would take 10 years and we have yet to see a significant acceleration to the pace of improvement.
FTC: We use income earning auto affiliate links.More.
What a week it was in college football: Five AP Top 25 teams lost to unranked opponents, and after No. 6 BYU’s defeat to Kansas, the Big 12 appears to be up for grabs after victories by Colorado and Arizona State.
The Buffaloes and Sun Devils have proved football fans wrong this season as Colorado is tied for the top spot in the Big 12 and Arizona State is a game behind. With both teams on a winning streak, what can they credit for their success?
After a rough start to the season, Billy Napier and Florida have turned things around and the Gators are one win from bowl eligibility. With an upset win over No. 22 LSU, is it time to stop questioning Napier?
Our college football experts break down key storylines and takeaways from Week 12.
Losses might be as important as wins in the CFP committee meeting room
With six new committee members, a new committee chair and a new College Football Playoff executive director, there are a lot of new faces at selection central. Each group is different. Ranking the top 25 teams is a subjective system, and this year’s committee appears to be putting an emphasis on losses — maybe more than in years past.
Who teams lose to and how has always mattered, but it might be more of a factor this year with multiple two-loss teams to sort through. It’s also a big reason why Ohio State is No. 2 and Penn State is No. 4 — close losses to highly-ranked teams. It’s never a good time for a bad loss, but it could mean the difference this year between a first-round bye, a first-round home game — or a seat on the couch. — Heather Dinich
Rivalries matter more than ever
Texas has never viewed Arkansas on par with rival Oklahoma, but Arkansas lives to torment Texas. Three years ago, the No. 15 Longhorns came to Fayetteville and were stomped 40-21. Jubilant Arkansas fans stormed the field.
But returning as conference rivals for the first time since the Razorbacks left the Southwest Conference in 1991 seemed to mean something to No. 3 Texas, too, after a tough 20-10 win over the 5-5 Razorbacks. “It was personal for sure,” senior edge rusher Barryn Sorrell said.
Quinn Ewers sealed the win by running for three yards on fourth-and-2 with 2:14 left. Rather than trying to evade linebacker Larry Worth III, Ewers decided to bull his way over him. “I just tried to put a little statement into it, that’s all,” Ewers said with a smile. “Just the history that these two programs have together, it’s going to be tough.”
Texas joining the SEC reconnected old grudge matches with Texas A&M and Arkansas. The 74,929 who showed up Saturday — the 10th-largest crowd in Arkansas history — threw their Horns Down at every opportunity. With an eight-game SEC schedule, there’s only one permanent rivalry guaranteed per school, and for the Longhorns, that will always be Oklahoma. Texas-Arkansas and Texas-Texas A&M could come and go. When college football is becoming more unrecognizable by the day, regional rivalries should be a priority. — Dave Wilson
Congrats to Colorado and Arizona State for proving us all wrong
It’s probably time to admit we were wrong about Deion Sanders’ Colorado and Kenny Dillingham’s Arizona State in 2024.
OK, maybe not all of us. But as both schools improved to 8-2 on Saturday, a preseason poll from CBS Sports resurfaced that ranked Sanders and Dillingham, respectively, as the 15th- and 16th-best coaches among the Big 12’s 16 football programs. And whether you had either coach/program that low in August, there can’t be many of us who expected either school to be here in Week 12: level alongside Iowa State for second in the Big 12 standings and in line to play at least some kind of role in the College Football Playoff picture over the final weeks of the regular season.
Colorado earned its fourth win in a row and Travis Hunter logged another entry to his Heisman Trophy résumé in a 49-24 win over Utah on Saturday, yet Sanders says the Buffaloes still “haven’t even played our best game.” Meanwhile, Arizona State reached its highest win total since 2021 on Saturday night after storming to a 21-0 first-half lead and holding off No. 16 Kansas State after halftime in a 24-14 road win, fueled by the aerial connection between Sam Leavitt (275 passing yards, three touchdowns) and Jordyn Tyson (12 catches, 176 yards, two touchdowns).
The successes at Colorado and Arizona State are a credit to the respective coaching jobs Sanders and Dillingham are executing. They’re also a credit to the concept that there remain many different paths to winning in a seemingly homogenized era of college football dominated by NIL, the transfer portal and the rest. Through 12 weeks, Colorado and Arizona State represent two of the sport’s great surprises this fall, and there are perhaps no two people more acutely aware of the doubters than the coaches leading this pair of impressive turnarounds in 2024.
“We were a three-win team twice,” Dillingham said Saturday night. “We were under NCAA sanctions. Most head coaches, to be brutally honest, you get fired if you take a job under sanctions. You don’t survive. You’re hired to be fired. That’s the nature of the beast. And right now we’re sitting here at 8-2 and couldn’t be prouder.” — Eli Lederman
South Carolina is clearly the nation’s best three-loss team
Shane Beamer’s team is not part of the logjam atop the SEC. The Gamecocks are not in the College Football Playoff mix, essentially eliminated Oct. 12 when they couldn’t hold a fourth-quarter lead at Alabama or tie the score in the closing minute. But since falling to 3-3 in Tuscaloosa, South Carolina has won four straight and continued to be one of the most consistently compelling squads on Saturdays.
After riding Kyle Kennard and the defense to wins over Oklahoma, Texas A&M and Vanderbilt, South Carolina needed the offense to outlast Missouri, going 70 yards in 47 seconds to score the winning touchdown with 15 seconds left. Redshirt freshman LaNorris Sellers is blossoming into one of the nation’s best young quarterbacks, as he set career highs for passing yards (353) and passing touchdowns (five) against Missouri. South Carolina has defeated three straight AP-ranked opponents for the first time in team history.
“We’re on the right track,” Beamer said. “The young players we have in this program right now, the quarterback, Dylan [Stewart]. You talk about the recruits that are here tonight, the ones that are committed to us. The best days of South Carolina football are right in front of us.”
There will be some what-ifs for the Gamecocks, especially in their losses to LSU and Alabama. But after a 5-7 season last fall, Beamer has recaptured his big-game magic and built a program that no opponent should want to face right now. — Adam Rittenberg
A resolute Billy Napier and his Florida team just keep getting back up
When it starts to go bad for a coach in the SEC, especially one who’s in his third season and has yet to manage a winning record, it’s usually like a two-ton truck cresting over an icy slope.
There’s no stopping the slide.
Even with the recent and dreaded vote of confidence for Florida’s Billy Napier, there are no guarantees about his future. But nobody would have predicted he had any future at Florida two months ago after an ugly home loss to Texas A&M, two weeks removed from a 41-17 beatdown by Miami at home. The speculation late that night was that Napier might be out as early as the next morning.
But he had just enough support in key areas to hang on, and most importantly, the players in his locker room still believed in him. And here we are, with two weeks left in the regular season, and the Gators are one win away from bowl eligibility after taking down LSU 27-16 at home Saturday. Another huge opportunity awaits this weekend when No. 11 Ole Miss visits the Swamp.
The Gators (5-5) have been resilient, just like their coach, and responded from a 49-17 blowout loss at Texas to play one of their most complete games of the season at home against LSU. Simply making a bowl game is hardly the standard at Florida, but the way Napier has kept his team together, continued to develop young quarterback DJ Lagway and gone about his business with accountability, humility and a quiet confidence is proof he deserves a fourth season to show he can get this program to that standard.
It’s time to get behind Napier and quit questioning him. It’s clear the Gators have a talented nucleus of younger players and that those players have their coach’s back. — Chris Low
Louisville … what are you doing?
Stanford vs. Louisville was an inconsequential game that should have flown under the radar, regardless of the result. And while the outcome — a Stanford win that ended a six-game losing streak — was a significant upset, it’s the way it happened that deserves some added attention. It might be the most improbable way a team has lost a game all season. Let’s dive in.
After trailing 35-21 in the fourth quarter, Stanford scored touchdowns with 6:37 left and 45 seconds left to cut the deficit to 35-34. At this point, I thought Stanford coach Troy Taylor, a coach who once went an entire high school season without punting, would go for the win with a 2-point conversion try. He did not. Tie score.
On the ensuing kickoff, Louisville opted against taking the ball at the 25-yard line and returned it to the 19. After a spike, a deep shot, a short pass and another deep shot all fail, Stanford took possession at its 45 with 4 seconds left. Overtime felt inevitable. Wrong.
Stanford completed a 1-yard pass only to be gifted 15 yards by an unsportsmanlike conduct penalty by Louisville, giving the Cardinal a chance to win the game on a 57-yard field goal attempt. Improbable, still. So, what does Louisville do: jumps offside to make the kick easier. And Stanford’s Emmet Kenney took advantage, making a 52-yard field goal as time expired.
An all-time collapse. — Kyle Bonagura
Kennesaw State’s Bohannon shows class on way out
Last weekend, Kennesaw State fired coach Brian Bohannon, who helped build the program from scratch nine years ago, then ushered it from the FCS into the FBS this season. That firing didn’t stop the former FCS Coach of the Year from supporting his players before its game Saturday against Sam Houston.
In a video posted by a Kennesaw State football alum, Bohannon showed up to the team’s pregame walk to the stadium and gave the players hugs and high-fives as they walked by.
The Owls ultimately lost in overtime to fall to 1-9 but showed fight against the Bearkats, who remain in contention for the Conference USA title.
Despite being fired, Bohannon should be revered in Kennesaw for taking the Owls to the FCS playoffs four times, for elevating the program to the FBS — and for the way he graciously exited. — Jake Trotter
Archaeologists have uncovered a remarkable 2,000-year-old Roman knife handle in Northumberland, England. The discovery, made in the River Tyne near Corbridge Roman Town, features a detailed depiction of a gladiator. This unique find sheds light on the influence and popularity of gladiators across the Roman Empire, including its farthest reaches in Britain.
As per a report by English Heritage, the handle, crafted from copper alloy, portrays a secutor gladiator, identifiable by his heavy armour and helmet. Secutors, named after the Latin term for “chaser,” were known for engaging in close combat against their agile counterparts, the retiarii. Notably, the figurine represents a left-handed fighter, a rarity in Roman culture, where left-handedness was often considered inauspicious. Researchers from English Heritage have suggested that this specific detail may indicate the handle was modelled after an actual gladiator, rather than serving as a general representation.
Gladiator Culture in the Roman Empire
Gladiatorial games were a significant feature of Roman public entertainment, drawing large crowds to amphitheatres across the empire. While these fighters were typically enslaved individuals or criminals, some gained celebrity status, despite their marginalised social standing. The events, often hosted by elite Roman citizens or emperors, aimed to display power and wealth.
Frances McIntosh, Collections Curator for Hadrian’s Wall and the North East at English Heritage, stated that gladiators’ popularity extended far beyond Rome, a fact underscored by the discovery of this artefact. Although memorabilia such as pottery and figurines have been documented, similar finds in Britain are considered rare.
Plans for Public Display
Corbridge Roman Town, originally established as a supply base in 79 AD, served as a key site during the Roman occupation of Britain until around 400 AD. English Heritage plans to exhibit the knife handle, along with other artefacts recovered from the river, at the Corbridge site next year.
This discovery continues to emphasise the enduring fascination with gladiators, both in ancient times and modern culture.