Connect with us

Published

on

PUMPKIN ECLIPSE — Mystery malware destroys 600,000 routers from a single ISP during 72-hour span An unknown threat actor with equally unknown motives forces ISP to replace routers.

Dan Goodin – May 30, 2024 2:00 pm UTC EnlargeGetty Images reader comments 0

One day last October, subscribers to an ISP known as Windstream began flooding message boards with reports their routers had suddenly stopped working and remained unresponsive to reboots and all other attempts to revive them.

The routers now just sit there with a steady red light on the front, one user wrote, referring to the ActionTec T3200 router models Windstream provided to both them and a next door neighbor. They won’t even respond to a RESET.

In the messageswhich appeared over a few days beginning on October 25many Windstream users blamed the ISP for the mass bricking. They said it was the result of the company pushing updates that poisoned the devices. Windstreams Kinetic broadband service has about 1.6 million subscribers in 18 states, including Iowa, Alabama, Arkansas, Georgia, and Kentucky. For many customers, Kinetic provides an essential link to the outside world.

We have 3 kids and both work from home, another subscriber wrote in the same forum. This has easily cost us $1,500+ in lost business, no tv, WiFi, hours on the phone, etc. So sad that a company can treat customers like this and not care.

After eventually determining that the routers were permanently unusable, Windstream sent new routers to affected customers. Black Lotus has named the event Pumpkin Eclipse. A deliberate act

A report published Thursday by security firm Lumen Technologies Black Lotus Labs may shed new light on the incident, which Windstream has yet to explain. Black Lotus Labs researchers said that over a 72-hour period beginning on October 25, malware took out more than 600,000 routers connected to a single autonomous system number belonging to an unnamed ISP.

While the researchers arent identifying the ISP, the particulars they report match almost perfectly with those detailed in the October messages from Windstream subscribers. Specifically, the date the mass bricking started, the router models affected, the description of the ISP, and the displaying of a static red light by the out-of-commission ActionTec routers. Windstream representatives declined to answer questions sent by email.

According to Black Lotus, the routersconservatively estimated at a minimum of 600,000were taken out by an unknown threat actor with equally unknown motivations. The actor took deliberate steps to cover their tracks by using commodity malware known as Chalubo, rather than a custom-developed toolkit. A feature built into Chalubo allowed the actor to execute custom Lua scripts on the infected devices. The researchers believe the malware downloaded and ran code that permanently overwrote the router firmware. Advertisement

We assess with high confidence that the malicious firmware update was a deliberate act intended to cause an outage, and though we expected to see a number of router make and models affected across the internet, this event was confined to the single ASN, Thursdays report stated before going on to note the troubling implications of a single piece of malware suddenly severing the connections of 600,000 routers.

The researchers wrote:

Destructive attacks of this nature are highly concerning, especially so in this case. A sizeable portion of this ISPs service area covers rural or underserved communities; places where residents may have lost access to emergency services, farming concerns may have lost critical information from remote monitoring of crops during the harvest, and health care providers cut off from telehealth or patients records. Needless to say, recovery from any supply chain disruption takes longer in isolated or vulnerable communities.

After learning of the mass router outage, Black Lotus began querying the Censys search engine for the affected router models. A one-week snapshot soon revealed that one specific ASN experienced a 49 percent drop in those models just as the reports began. This amounted to the disconnection of at least 179,000 ActionTec routers and more than 480,000 routers sold by Sagemcom. EnlargeBlack Lotus Labs

The constant connecting and disconnecting of routers to any ISP complicates the tracking process, because its impossible to know if a disappearance is the result of the normal churn or something more complicated. Black Lotus said that a conservative estimate is that at least 600,000 of the disconnections it tracked were the result of Chaluba infecting the devices and, from there, permanently wiping the firmware they ran on.

After identifying the ASN, Black Lotus discovered a complex multi-path infection mechanism for installing Chaluba on the routers. The following graphic provides a logical overview. EnlargeBlack Lotus Labs

Further ReadingMystery solved in destructive attack that knocked out >10k Viasat modemsThere aren’t many known precedents for malware that wipes routers en masse in the way witnessed by the researchers. Perhaps the closest was the discovery in 2022 of AcidRain, the name given to malware that knocked out 10,000 modems for satellite Internet provider Viasat. The outage, hitting Ukraine and other parts of Europe, was timed to Russia’s invasion of the smaller neighboring country.

A Black Lotus representative said in an interview that researchers can’t rule out that a nation-state is behind the router-wiping incident affecting the ISP. But so far, the researchers say they aren’t aware of any overlap between the attacks and any known nation-state groups they track. Advertisement

The researchers have yet to determine the initial means of infecting the routers. It’s possible the threat actors exploited a vulnerability, although the researchers said they aren’t aware of any known vulnerabilities in the affected routers. Other possibilities are the threat actor abused weak credentials or accessed an exposed administrative panel. An attack unlike any other

While the researchers have analyzed attacks on home and small office routers before, they said two things make this latest one stand out. They explained:

First, this campaign resulted in a hardware-based replacement of the affected devices, which likely indicates that the attacker corrupted the firmware on specific models. The event was unprecedented due to the number of units affectedno attack that we can recall has required the replacement of over 600,000 devices. In addition, this type of attack has only ever happened once before, with AcidRain used as a precursor to an active military invasion.

They continued:

The second unique aspect is that this campaign was confined to a particular ASN. Most previous campaigns weve seen target a specific router model or common vulnerability and have effects across multiple providers networks. In this instance, we observed that both Sagemcom and ActionTec devices were impacted at the same time, both within the same providers network.This led us to assess it was not the result of a faulty firmware update by a single manufacturer, which would normally be confined to one device model or models from a given company. Our analysis of the Censys data shows the impact was only for the two in question. This combination of factors led us to conclude the event was likely a deliberate action taken by an unattributed malicious cyber actor, even if we were not able to recover the destructive module.

With no clear idea how the routers came to be infected, the researchers can only offer the usual generic advice for keeping such devices free of malware. That includes installing security updates, replacing default passwords with strong ones, and regular rebooting. ISPs and other organizations that manage routers should follow additional advice for securing the management interfaces or administering the devices.

Thursday’s report includes IP addresses, domain names, and other indicators that people can use to determine if their devices have been targeted or compromised in the attacks. reader comments 0 Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Related Stories Today on Ars

Continue Reading

World

Migrants locked up in notorious El Salvador jail released in Venezuela-US prisoner swap

Published

on

By

Migrants locked up in notorious El Salvador jail released in Venezuela-US prisoner swap

On Friday, Paola Paiva waited in a hotel near Caracas airport, nervous but giddy with excitement to be reunited with her brother, finally.

For five months, Arturo Suarez has been detained in a notorious prison in El Salvador.

“I am going to wait for my brother to call me,” she told Sky News, “and after giving him a hug, I want to just listen to him, listen to his voice. Let him talk and tell us his story.”

Suarez was one of the more than 250 Venezuelan migrants who had been living in America but were arrested in immigration raids by the Trump administration and sent to El Salvador, a showpiece act in the president’s promise to deport millions of migrants.

Paola Paiva holds a vigil for brother Arturo Suarez. Pic: Reuters
Image:
Paola Paiva holds a vigil for brother Arturo Suarez. Pic: Reuters

Most of the men had never even been to El Salvador before. Their detention has been controversial because the White House claims the men are all part of the dangerous Tren de Aragua gang but has provided little evidence to support this assertion.

The only evidence Paola had that Suarez was still alive was a picture of him published on a news website showing the inside of the maximum security CECOT jail.

He is one of dozens of men with their hands and feet cuffed, heads shaved and bodies shackled together.

More on El Salvador

Now he is returning to his home country, one of the bargaining chips in a deal that saw the release of ten Americans and US permanent residents who had been seized by the Venezuelan authorities.

Venezuelans arrive back in home country after being detained in El Salvador
Image:
Venezuelans arrive back in home country after being detained in El Salvador

Paola had tried to go to the airport to greet her brother as he disembarked a charter plane bringing the men back from El Salvador but authorities told her to wait at a nearby hotel.

“They told us they are taking them all to a hotel to rest,” she said.

“But I managed to get someone to give my phone number on a piece of paper to my brother, so I am expecting his call tomorrow, as soon as he can access a phone.

“We heard they are going to perform some medical exams on them and check their criminal records,” she added. “I’m not afraid; I’m not worried since my brother has a clean record.

“I am so happy. I knew this day would happen, and that it would be unexpected, that no one was going to notify us. I knew it was going to be a total surprise.”

US citizens released from Venezuela. Pic: Reuters
Image:
US citizens released from Venezuela. Pic: Reuters

The Trump administration had paid the El Salvador government, led by President Nayib Bukele, millions of dollars to imprison the men.

Homeland security secretary Kristi Noem visited CECOT last month, posing in front of prisoners for a photo opportunity.

Read more from Sky News:
Trump suing Wall Street Journal for $10bn after Epstein letter report
Tech company investigating viral footage of Coldplay concert couple

But Cristosal, an international human rights group based in El Salvador, says it has “documented systematic physical beatings, torture, intentional denial of access to food, water, clothing, health care,” inside the prison.

A video which was seemingly filmed aboard the charter flight bringing the Venezuelan migrants back to Caracas shows Arturo briefly talking about his experience inside.

He looks physically well but speaks into the camera and says: “We were four months with no communication, no phone calls, kidnapped, we didn’t know what (the) day was, not even the time.

“We were beat up at breakfast, lunch and dinner,” he continues.

Sky News interviewed Arturo Suarez‘s brother Nelson near his home in the US in April, weeks after Arturo – an aspiring singer – had been arrested by immigration and customs enforcement (ICE) agents while filming a music video inside a house.

Nelson said he believed Arturo’s only crime was “being Venezuelan and having tattoos.” He showed me documents that indicate Arturo has no criminal record in Venezuela, Chile, Colombia or the United States, the four countries he has lived in.

Now Nelson is delighted Arturo is being released – but worries for his future.

“The only thing that casts a shadow in such a moment of joy is that bit of anger when I think that all the governments involved are going to use my brother’s story, and the others on that flight, as political gain,” he said.

“Each of them will tell a different story, making themselves the heroes, when the reality is that many innocent people suffered unfairly and unnecessarily, and many families will remain separated after this incident due to politics, immigration and fear.”

Continue Reading

World

Ha Long Bay: At least 34 dead after tourist boat capsizes in Vietnam

Published

on

By

Ha Long Bay: At least 34 dead after tourist boat capsizes in Vietnam

At least 34 people have died after a tourist boat capsized in Vietnam, according to state media reports.

The Wonder Sea boat was reportedly carrying 53 people, including five crew members, when it capsized due to strong winds in Ha Long Bay on Saturday.

It happened at roughly 2pm local time (7am GMT). Rescue teams have found 11 survivors and recovered 34 bodies, eight of them children, the state-run Vietnam News Agency said, citing local authorities.

People on a capsized tourist boat being rescued in Ha Long Bay, Vietnam. Pic: QDND via AP
Image:
Rescuer in Ha Long Bay are searching for survivors. Pic: QDND via AP

The People’s Army Newspaper, which cited local border guards, said authorities have not yet confirmed details about the tourists, including their nationalities, as the rescue operation continues.

Most of the passengers were tourists, including about 20 children, from the country’s capital city, Hanoi, the newspaper said.

The incident comes shortly after the arrival of Storm Wipha in the South China Sea, bringing strong winds, heavy rain and lightning to the area.

A body being carried on stretcher after a tourist boat capsized in Ha Long Bay, Vietnam. Pic: QDND via AP
Image:
A body being carried on stretcher after a tourist boat capsized in Ha Long Bay, Vietnam. Pic: QDND via AP

The named storm is the third typhoon to hit the South China Sea this year, and is expected to make landfall along the northern coast of Vietnam early next week.

More on Vietnam

Disruptions linked to the storm have also had an impact on air travel, according to Noi Bai Airport.

The airport reported that nine incoming flights were diverted to other airports, while three outgoing flights were temporarily grounded due to adverse weather conditions.

Tourist boats cruise in Halong Bay. File pic: Reuters
Image:
Tourist boats cruise in Halong Bay. File pic: Reuters

The winds brought by Storm Wipha reached up to 63mph (101kmph) and gusts of up to 68mph (126kmph) as it passed south of Taiwan on Saturday, according to the island’s Central News Agency.

Read more from Sky News:
‘Evil serial killer’ might have more victims
Tech firm boss on leave after Coldplay concert footage

Ha Long Bay is around 125mi (200km) north east of Hanoi and attracts tens of thousands of visitors each year.

Of those who visit Ha Long Bay, many choose to take overnight boat tours to further explore the area.

Continue Reading

World

Gaza: More than 30 people killed ‘as Israeli troops open fire towards Palestinians waiting for aid’

Published

on

By

Gaza: More than 30 people killed 'as Israeli troops open fire towards Palestinians waiting for aid'

More than 30 people have been killed after Israeli troops opened fire towards crowds of Palestinians waiting for aid, according to witnesses and hospital officials.

The deaths occurred near distribution hubs operated by the US-Israeli-backed Gaza Humanitarian Foundation (GHF), which began distributing food packages in Gaza at the end of May, after Israel eased its 11-week blockade of aid into the territory.

At least 32 people were killed on Saturday, according to the Hamas-run Gaza health ministry, while a further 100 people were injured, according to local reports.

Most of the deaths came as Palestinians massed in the Teina area, around 3km (2 miles) away from a GHF aid distribution centre east of the city of Khan Younis.

More than 3o killed near aid distribution centres. Pic:Mariam Dagga/AP
Image:
More than 30 people killed near aid distribution centres. Pic: Mariam Dagga/AP

Mahmoud Mokeimar said he was walking with crowds of people – mostly young men – towards the food hub when troops fired warning shots as the crowd advanced, before opening fire towards the marching people.

“It was a massacre… the occupation opened fire at us indiscriminately,” he said.

Injured Palestinians are brought to Nasser Hospital in Khan Younis. Pic: Mariam Dagga/AP
Image:
Injured Palestinians are brought to Nasser Hospital in Khan Younis. Pic: Mariam Dagga/AP

Akram Aker said troops fired machine guns mounted on tanks and drones.

More on Israel-hamas War

“They encircled us and started firing directly at us,” he said.

The Nasser Hospital in Khan Younis said it received 25 bodies, along with dozens of wounded.

Seven other people, including one woman, were killed in the Shakoush area, hundreds of yards north of another GHF hub in Gaza’s southernmost city of Rafah, the hospital said.

The army and GHF did not immediately comment on Saturday’s violence.

Follow The World
Follow The World

Listen to The World with Richard Engel and Yalda Hakim every Wednesday

Tap to follow

The GFH, which has four distribution centres, three of which are in the southern Gaza Strip, says it has distributed millions of meals to hungry Palestinians.

But local health officials and witnesses say hundreds of people have been killed by Israeli army fire as they try to reach the distribution hubs.

The GHF, which employs private armed guards, says there have been no deadly shootings at its sites, though this week, 20 people were killed at one of its locations, most of them in a stampede.

Read more from Sky News:
The Syrian city engulfed in tribal violence
Migrants freed from notorious El Salvador jail in Venezuela-US prisoner swap

The group accused Hamas agitators of causing a panic, but gave no evidence to back the claim.

The army, which is not at the sites but secures them from a distance, says it only fires warning shots if crowds get too close to its forces.

The 21-month war in Gaza was triggered when Hamas militants stormed into southern Israel on 7 October 2023, killing 1,200 people and taking 250 others hostage.

An Israeli military offensive has killed more than 58,000 Palestinians, according to the Gaza health ministry, while Gaza’s more than two million Palestinians are living through a catastrophic humanitarian crisis.

Israel and Hamas have been holding ceasefire talks in Qatar in recent weeks, but international mediators say there have been no breakthroughs.

US President Donald Trump said another 10 hostages will be released from Gaza shortly, without providing details.

Continue Reading

Trending