Midwest Meltdown: How ‘Pumpkin Eclipse’ Botnet Bricked 600,000 Routers

Pumpkin Eclipse, a malware botnet, bricked 600,000 SOHO routers in October 2023, disrupting internet access across the Midwest. Black Lotus Labs identified the attack, which mainly affected a single ISP and three router models. The incident left users scrambling to replace their routers to restore…

Hot Take:

When life gives you pumpkins, make a botnet and ruin everyone’s day! ‘Pumpkin Eclipse’ proved there’s nothing quite like a Halloween trick that bricks your internet router and treats you to a trip to the electronics store!

Key Points:

  • ‘Pumpkin Eclipse’ botnet took 600,000 routers offline, leaving users with no option but to replace them.
  • The incident disrupted internet access across numerous Midwest states between October 25 and October 27, 2023.
  • Only affected a single ISP and three specific router models (ActionTec T3200s, ActionTec T3260s, Sagemcom F5380).
  • The botnet used a series of scripts to execute the primary payload, ‘Chalubo,’ which operates from memory to evade detection.
  • Despite the large-scale attack, the botnet did not perform any Distributed Denial of Service (DDoS) attacks.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here