Connect with us

Published

on

PUMPKIN ECLIPSE — Mystery malware destroys 600,000 routers from a single ISP during 72-hour span An unknown threat actor with equally unknown motives forces ISP to replace routers.

Dan Goodin – May 30, 2024 2:00 pm UTC EnlargeGetty Images reader comments 0

One day last October, subscribers to an ISP known as Windstream began flooding message boards with reports their routers had suddenly stopped working and remained unresponsive to reboots and all other attempts to revive them.

The routers now just sit there with a steady red light on the front, one user wrote, referring to the ActionTec T3200 router models Windstream provided to both them and a next door neighbor. They won’t even respond to a RESET.

In the messageswhich appeared over a few days beginning on October 25many Windstream users blamed the ISP for the mass bricking. They said it was the result of the company pushing updates that poisoned the devices. Windstreams Kinetic broadband service has about 1.6 million subscribers in 18 states, including Iowa, Alabama, Arkansas, Georgia, and Kentucky. For many customers, Kinetic provides an essential link to the outside world.

We have 3 kids and both work from home, another subscriber wrote in the same forum. This has easily cost us $1,500+ in lost business, no tv, WiFi, hours on the phone, etc. So sad that a company can treat customers like this and not care.

After eventually determining that the routers were permanently unusable, Windstream sent new routers to affected customers. Black Lotus has named the event Pumpkin Eclipse. A deliberate act

A report published Thursday by security firm Lumen Technologies Black Lotus Labs may shed new light on the incident, which Windstream has yet to explain. Black Lotus Labs researchers said that over a 72-hour period beginning on October 25, malware took out more than 600,000 routers connected to a single autonomous system number belonging to an unnamed ISP.

While the researchers arent identifying the ISP, the particulars they report match almost perfectly with those detailed in the October messages from Windstream subscribers. Specifically, the date the mass bricking started, the router models affected, the description of the ISP, and the displaying of a static red light by the out-of-commission ActionTec routers. Windstream representatives declined to answer questions sent by email.

According to Black Lotus, the routersconservatively estimated at a minimum of 600,000were taken out by an unknown threat actor with equally unknown motivations. The actor took deliberate steps to cover their tracks by using commodity malware known as Chalubo, rather than a custom-developed toolkit. A feature built into Chalubo allowed the actor to execute custom Lua scripts on the infected devices. The researchers believe the malware downloaded and ran code that permanently overwrote the router firmware. Advertisement

We assess with high confidence that the malicious firmware update was a deliberate act intended to cause an outage, and though we expected to see a number of router make and models affected across the internet, this event was confined to the single ASN, Thursdays report stated before going on to note the troubling implications of a single piece of malware suddenly severing the connections of 600,000 routers.

The researchers wrote:

Destructive attacks of this nature are highly concerning, especially so in this case. A sizeable portion of this ISPs service area covers rural or underserved communities; places where residents may have lost access to emergency services, farming concerns may have lost critical information from remote monitoring of crops during the harvest, and health care providers cut off from telehealth or patients records. Needless to say, recovery from any supply chain disruption takes longer in isolated or vulnerable communities.

After learning of the mass router outage, Black Lotus began querying the Censys search engine for the affected router models. A one-week snapshot soon revealed that one specific ASN experienced a 49 percent drop in those models just as the reports began. This amounted to the disconnection of at least 179,000 ActionTec routers and more than 480,000 routers sold by Sagemcom. EnlargeBlack Lotus Labs

The constant connecting and disconnecting of routers to any ISP complicates the tracking process, because its impossible to know if a disappearance is the result of the normal churn or something more complicated. Black Lotus said that a conservative estimate is that at least 600,000 of the disconnections it tracked were the result of Chaluba infecting the devices and, from there, permanently wiping the firmware they ran on.

After identifying the ASN, Black Lotus discovered a complex multi-path infection mechanism for installing Chaluba on the routers. The following graphic provides a logical overview. EnlargeBlack Lotus Labs

Further ReadingMystery solved in destructive attack that knocked out >10k Viasat modemsThere aren’t many known precedents for malware that wipes routers en masse in the way witnessed by the researchers. Perhaps the closest was the discovery in 2022 of AcidRain, the name given to malware that knocked out 10,000 modems for satellite Internet provider Viasat. The outage, hitting Ukraine and other parts of Europe, was timed to Russia’s invasion of the smaller neighboring country.

A Black Lotus representative said in an interview that researchers can’t rule out that a nation-state is behind the router-wiping incident affecting the ISP. But so far, the researchers say they aren’t aware of any overlap between the attacks and any known nation-state groups they track. Advertisement

The researchers have yet to determine the initial means of infecting the routers. It’s possible the threat actors exploited a vulnerability, although the researchers said they aren’t aware of any known vulnerabilities in the affected routers. Other possibilities are the threat actor abused weak credentials or accessed an exposed administrative panel. An attack unlike any other

While the researchers have analyzed attacks on home and small office routers before, they said two things make this latest one stand out. They explained:

First, this campaign resulted in a hardware-based replacement of the affected devices, which likely indicates that the attacker corrupted the firmware on specific models. The event was unprecedented due to the number of units affectedno attack that we can recall has required the replacement of over 600,000 devices. In addition, this type of attack has only ever happened once before, with AcidRain used as a precursor to an active military invasion.

They continued:

The second unique aspect is that this campaign was confined to a particular ASN. Most previous campaigns weve seen target a specific router model or common vulnerability and have effects across multiple providers networks. In this instance, we observed that both Sagemcom and ActionTec devices were impacted at the same time, both within the same providers network.This led us to assess it was not the result of a faulty firmware update by a single manufacturer, which would normally be confined to one device model or models from a given company. Our analysis of the Censys data shows the impact was only for the two in question. This combination of factors led us to conclude the event was likely a deliberate action taken by an unattributed malicious cyber actor, even if we were not able to recover the destructive module.

With no clear idea how the routers came to be infected, the researchers can only offer the usual generic advice for keeping such devices free of malware. That includes installing security updates, replacing default passwords with strong ones, and regular rebooting. ISPs and other organizations that manage routers should follow additional advice for securing the management interfaces or administering the devices.

Thursday’s report includes IP addresses, domain names, and other indicators that people can use to determine if their devices have been targeted or compromised in the attacks. reader comments 0 Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Related Stories Today on Ars

Continue Reading

UK

How e-bike riders are doing double the speed limit – and many of them work for fast food delivery firms

Published

on

By

How e-bike riders are doing double the speed limit - and many of them work for fast food delivery firms

It’s lunchtime on Birmingham’s New Street. 

Close to its many restaurants, food delivery riders are congregating on their bikes.

The area is packed with shoppers and workers.

PC Paige Gartlan is approaching with other officers. She’s on the lookout for illegally modified e-bikes – and she knows she’ll find them here.

“You can physically tell by looking at the bike that it’s generally going to be illegal – the battery pack is taped on to the sides and generally the size of the motor that’s on the back wheel,” she explains.

Sky News has been invited on an operation by West Midlands Police to find these bikes and get them off the streets.

PC Gartlan has been hit by one before. She’s had to tackle a rider to the floor after he drove into her.

More on Birmingham

Within minutes, she’s spotted a suspicious-looking bike. The rider makes a run for it – followed by plain-clothed officers.

PC Gartlan tests the bike – it’s showing a top speed of 52km/hr on the speedometer – just over 30mph.

PC Paige Gartlan with a seized e-bike
Image:
PC Paige Gartlan with a seized e-bike

The speed limit for e-bikes in the UK is 15.5mph when using electric power for assistance.

I look up the street and another two riders have been detained. In less than an hour, officers have confiscated four bikes – all were being ridden by fast food delivery drivers.

The commotion is attracting a lot of attention.

“They are dangerous,” Sandra, who has just finished work, tells me.

Demoz had his bike taken by police
Image:
Demoz had his bike taken by police

She’s stood watching the riders being questioned. She says she’s had near-misses herself and is worried for the safety of the elderly and children.

It’s not just West Midlands police officers here – immigration officials are carrying out checks too. They’re involved in a nationwide operation, which has seen more than 7,000 arrests in the last year – a 50% increase on last year.

Matthew Foster, the immigration enforcement lead officer for the West Midlands, tells me they’ve already found one individual who has entered the UK unlawfully.

“He’s been detained,” he says, “to affect his removal from the UK.”

Further down the street, police are loading illegally modified bikes on to a van – they’re destined to be crushed. One of them had belonged to Demoz.

Read more:
Non-folding e-bikes banned on London Tube
E-bike and e-scooter crimes soar 730% in five years

A e-bike that was seized by police in West Midlands
Image:
An e-bike seized by West Midlands Police

He’s on his way home, carrying a big box with the logo of one of the main fast food delivery firms on it.

He tells me he used to have an illegal bike, but he thought his new one was legal.

“I make a mistake, I have to say sorry, I will do better for the future,” he says.

I get in touch with the big delivery firms; Deliveroo, Uber Eats, and Just Eat.

Their representatives say they constantly remind workers of their safety obligations, and that they’re all working closely with the government to increase security checks on riders.

As he leaves, Demoz, now bike-free, tells me he’s thinking of changing his job.

Continue Reading

UK

I can’t help feel Harry’s team are trying to push the reset button – here’s why

Published

on

By

I can't help feel Harry's team are trying to push the reset button - here's why

Watching pictures of Prince Harry in Angola this week took me back to 2019, when we were there for his first visit following in Princess Diana’s footsteps.

The pictures on Wednesday looked so similar; his effortless interactions with people who face the daily dangers of landmines, and his obvious passion to help a charity that he cares deeply about.

Of course so much has happened in the six years since then, but with other headlines this week, I couldn’t help but feel like we could be looking at the beginning of a reset for Harry.

It started last Saturday night, as the story emerged of a meeting between the King’s communications secretary, Harry’s new London-based head of PR, and Harry’s most senior aide in America.

Three people you may not have heard of, but a meeting that was quickly described as “peace talks”.

File photo dated 12/12/18 of King Charles III, then Prince of Wales, and the Duke of Sussex during a discussion about violent youth crime at a forum held at Clarence House in London. The Duke of Sussex's relationship with the King remains "distant", with Harry's letters and calls to his father going unanswered, sources have said. Issue date: Tuesday April 15, 2025.
Image:
The King and Prince Harry in 2018. Pic: PA

The pictures of the get-together were being sold for thousands of pounds by the paper that ran them, just one indication of the global fascination about whether father and son may be on the road to reconciliation.

Neither side are willing to go there when you ask what exactly they talked about, although I suspect some of it was much more practical than about trying to mend this fractured relationship.

More on Prince Harry

Things like trying to avoid unnecessary negative stories, for example, the kind where Harry is accused of snubbing his father because they just happen to be doing jobs on the same day.

Prince Harry meets landmine victim Sandra Tigica in Angola in 2019, who Princess Diana met on her visit to Angola in 1997.
Image:
Prince Harry meets landmine victim Sandra Tigica in Angola in 2019, who Princess Diana met on her visit to Angola in 1997

It’s tricky for Harry’s camp to avoid such a situation when they don’t have sight of the King’s diary.

There’s also been the chatter about who may, or may not, have leaked the meeting.

There has been speculation around why they were out on a balcony, and who spotted the photographer in the park.

But whether it was a leak, or just a really good spot from a journalist or photographer, it’s not a bad thing for either side that we’re now all talking about whether father and son may be close to patching things up.

It did however raise other questions, about what it means for Prince William and his relationship with his brother.

So far there have been no indications of any meeting between William’s team and that of his brother.

The feelings of William also, you may think, a consideration for the King.

File photo dated 12/12/18 of King Charles III, then Prince of Wales, and the Duke of Sussex during a discussion about violent youth crime at a forum held at Clarence House in London. The Duke of Sussex's relationship with the King remains "distant", with Harry's letters and calls to his father going unanswered, sources have said. Issue date: Tuesday April 15, 2025.
Image:
The King and Prince Harry in 2018. Pic: PA

The unexpected headlines around Harry just kept coming, as on Tuesday he popped up in Angola.

His second visit there, this time with no press pack in tow.

So why the surprise visit?

Harry has worked with the Halo Trust for some time, and it’s clearly still a priority for them to highlight the dangers faced by those living with the potential dangers of landmines in Angola.

But it also feels like part of a push to get Harry out on more public engagements.

I’ve been told that since moving away from the UK he has continued to have regular contact with those charities with which he’s maintained ties, but being on the phone or a video call, isn’t the same as physically being there in person.

We saw something similar with his trip to China with Travalyst earlier this year, some may argue not the best choice of destination, but another example of wanting to get him physically out on visits to reinforce publicly those connections with causes that matter so much to him.

Read more:
Palace confirms date of Trump’s state visit

King’s state banquet for Macron in pictures

Please use Chrome browser for a more accessible video player

Prince Harry follows in Diana’s footsteps

For some months now it’s felt like Meghan has regained an element of control over how she wants to be seen.

Just look at her social media accounts and the success of her “As Ever” brand.

Whether Harry for the first time would step on to the social media scene with his own public account we wait to see, although the idea of his own commercial project is more likely, with suggestions something may be in the pipeline, we wait and see what.

After a constant flow of stories in recent months relating to court cases or his ongoing row with his family, this week has felt different.

A lot has been made about Harry and Meghan establishing a new “court” and what lies behind their decision to hire new people, five years after they stepped away from royal life.

There are of course elements of the recent past that it is impossible to erase, even Harry, in his recent interview talked of how he would “love reconciliation with my family” but added, “Of course, some members of my family will never forgive me for writing a book. Of course, they will never forgive me for… lots of things.”

But it does feel like their new team are tentatively attempting to push the reset button; getting Harry out on more engagements just one way they hope to focus our minds back on to what he has always done best.

Continue Reading

World

Migrants locked up in notorious El Salvador jail released in Venezuela-US prisoner swap

Published

on

By

Migrants locked up in notorious El Salvador jail released in Venezuela-US prisoner swap

On Friday, Paola Paiva waited in a hotel near Caracas airport, nervous but giddy with excitement to be reunited with her brother, finally.

For five months, Arturo Suarez has been detained in a notorious prison in El Salvador.

“I am going to wait for my brother to call me,” she told Sky News, “and after giving him a hug, I want to just listen to him, listen to his voice. Let him talk and tell us his story.”

Suarez was one of the more than 250 Venezuelan migrants who had been living in America but were arrested in immigration raids by the Trump administration and sent to El Salvador, a showpiece act in the president’s promise to deport millions of migrants.

Paola Paiva holds a vigil for brother Arturo Suarez. Pic: Reuters
Image:
Paola Paiva holds a vigil for brother Arturo Suarez. Pic: Reuters

Most of the men had never even been to El Salvador before. Their detention has been controversial because the White House claims the men are all part of the dangerous Tren de Aragua gang but has provided little evidence to support this assertion.

The only evidence Paola had that Suarez was still alive was a picture of him published on a news website showing the inside of the maximum security CECOT jail.

He is one of dozens of men with their hands and feet cuffed, heads shaved and bodies shackled together.

More on El Salvador

Now he is returning to his home country, one of the bargaining chips in a deal that saw the release of ten Americans and US permanent residents who had been seized by the Venezuelan authorities.

Venezuelans arrive back in home country after being detained in El Salvador
Image:
Venezuelans arrive back in home country after being detained in El Salvador

Paola had tried to go to the airport to greet her brother as he disembarked a charter plane bringing the men back from El Salvador but authorities told her to wait at a nearby hotel.

“They told us they are taking them all to a hotel to rest,” she said.

“But I managed to get someone to give my phone number on a piece of paper to my brother, so I am expecting his call tomorrow, as soon as he can access a phone.

“We heard they are going to perform some medical exams on them and check their criminal records,” she added. “I’m not afraid; I’m not worried since my brother has a clean record.

“I am so happy. I knew this day would happen, and that it would be unexpected, that no one was going to notify us. I knew it was going to be a total surprise.”

US citizens released from Venezuela. Pic: Reuters
Image:
US citizens released from Venezuela. Pic: Reuters

The Trump administration had paid the El Salvador government, led by President Nayib Bukele, millions of dollars to imprison the men.

Homeland security secretary Kristi Noem visited CECOT last month, posing in front of prisoners for a photo opportunity.

Read more from Sky News:
Trump suing Wall Street Journal for $10bn after Epstein letter report
Tech company investigating viral footage of Coldplay concert couple

But Cristosal, an international human rights group based in El Salvador, says it has “documented systematic physical beatings, torture, intentional denial of access to food, water, clothing, health care,” inside the prison.

A video which was seemingly filmed aboard the charter flight bringing the Venezuelan migrants back to Caracas shows Arturo briefly talking about his experience inside.

He looks physically well but speaks into the camera and says: “We were four months with no communication, no phone calls, kidnapped, we didn’t know what (the) day was, not even the time.

“We were beat up at breakfast, lunch and dinner,” he continues.

Sky News interviewed Arturo Suarez‘s brother Nelson near his home in the US in April, weeks after Arturo – an aspiring singer – had been arrested by immigration and customs enforcement (ICE) agents while filming a music video inside a house.

Nelson said he believed Arturo’s only crime was “being Venezuelan and having tattoos.” He showed me documents that indicate Arturo has no criminal record in Venezuela, Chile, Colombia or the United States, the four countries he has lived in.

Now Nelson is delighted Arturo is being released – but worries for his future.

“The only thing that casts a shadow in such a moment of joy is that bit of anger when I think that all the governments involved are going to use my brother’s story, and the others on that flight, as political gain,” he said.

“Each of them will tell a different story, making themselves the heroes, when the reality is that many innocent people suffered unfairly and unnecessarily, and many families will remain separated after this incident due to politics, immigration and fear.”

Continue Reading

Trending