Midwest Mayhem: ‘Pumpkin Eclipse’ Botnet Destroys 600,000 Routers, Leaves ISP in the Dark

In October 2023, the ‘Pumpkin Eclipse’ botnet bricked 600,000 routers in the Midwest, leaving users offline and puzzled. The attack targeted a single ISP’s routers, causing a 49% drop in operating modems. Researchers at Black Lotus Labs are still trying to determine how the malware…

Hot Take:

Looks like Halloween came early in 2023 with the ‘Pumpkin Eclipse’ botnet scaring the bejeezus out of 600,000 routers! Who knew trick-or-treating could be this catastrophic?

Key Points:

  • ‘Pumpkin Eclipse’ botnet bricked 600,000 routers across the Midwest between October 25 and October 27, 2023.
  • Incident specifically impacted a single unnamed ISP, resembling a Windstream outage reported during the same time.
  • Only three router models were affected: ActionTec T3200s, ActionTec T3260s, and Sagemcom F5380.
  • Botnet used a script called ‘get_scrpc’ to fetch and execute its primary payload, ‘Chalubo’.
  • Despite its DDoS capabilities, botnet was utilized solely for destructive purposes, causing a 49% reduction in the ISP’s modems.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here