Mystery hacking group bricked 600,000 modems in the US
It used to be the case you could reset your hardware, but this is the second example of malware bricking hardware with no way to recover or restart it.
Key takeaways
- The cyber attack, which wasn't reported at the time, took place over a 72-hour period between October 25 and 27, 2023.
- Black Lotus revealed the unknown attackers broke the 600,000-plus routers using Chalubo – a Remote Access Trojan (RAT), variants of which in the past have been used to blow up chemical plants.
- The malware has been around since 2018 and has built-in features to encrypt communications with the command-and-control server, perform Distributed-Denial-of-Service attacks, and execute Lua scripts on infected devices.
Cite or link to this article
Griffin, M. (2024) 'Mystery hacking group bricked 600,000 modems in the US', 311 Institute, 15 July. Available at: https://www.311institute.com/mystery-hacking-group-bricked-600000-modems-in-the-us/ (Accessed: 1 October 2026).
A while ago I spoke about how a mystery hacking group managed to brick, in other words physically disable and ergo ruin, E-Mail routers from Baraccuda Networks. And now it’s happened again but on a much larger – and smaller – scale after unknown miscreants it’s reported broke into more than 600,000 routers belonging to a single ISP late last year and deployed malware on the devices before totally disabling them, according to security researchers.
The cyber attack, which wasn't reported at the time, took place over a 72-hour period between October 25 and 27, 2023. It "rendered the infected devices permanently inoperable, and required a hardware-based replacement," according to US telco Lumen Technologies' Black Lotus Labs, which published details about the destructive event on Thursday and named it "Pumpkin Eclipse."
The Future of. Cyber Security, by keynote Matthew Griffin
It seems the mysterious intruders specifically targeted two different routers – ActionTec's T3200 and T3260 – but it's unclear how they gained access.
"When searching for exploits impacting these models in [vulnerability alerting platform] OpenCVE for ActionTec, none were listed for the two models in question, suggesting the threat actor likely either abused weak credentials or exploited an exposed administrative interface," the Black Lotus researchers opined – without naming the impacted ISP. It's been speculated that Arkansas-based Windstream was the victim, but the ISP declined to comment.
Black Lotus revealed the unknown attackers broke the 600,000-plus routers using Chalubo – a Remote Access Trojan (RAT), variants of which in the past have been used to blow up chemical plants.
The malware has been around since 2018 and has built-in features to encrypt communications with the command-and-control server, perform Distributed-Denial-of-Service attacks, and execute Lua scripts on infected devices. Oddly, the criminals didn't use the DDoS functionality, we're told.
What if you could brick a Smart City?
"At this time, we do not have an overlap between this activity and any known nation-state activity clusters," the threat hunters wrote.
Specifically, there's no overlap with China's Volt Typhoon, which also has an affinity for infecting routers, or Russia's Sandworm, aka SeaShell Blizzard, another crew known for destructive attacks.
The researchers added that this specific type of attack has only ever been seen once before: the AcidRain wiper case, which has been attributed to Sandworm and was used to take out KA-SAT modems used in Ukraine as a prelude to Russia's invasion.
Black Lotus asserts a high level of confidence that "the malicious firmware update was a deliberate act intended to cause an outage, and though we expected to see a number of router make and models affected across the internet, this event was confined to the single ASN [Autonomous System Number]."
FAQ
Why does this matter?
It used to be the case you could reset your hardware, but this is the second example of malware bricking hardware with no way to recover or restart it.

About the author
Matthew Griffin Founder, 311 Institute
Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath."
Read full bio
Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath." 15-time best selling author of the "Codex of the Future" series, Matthew is the Founder and Futurist in Chief of the 311 Institute, a global Futures and Deep Futures advisory firm working with royal households, world leaders, G7, G20, and G77 governments, NGOs, and multi-national mid and mega cap firms to help them explore, shape, and lead the next 50 years of business and society.
An award-winning YouTube creator with over a million followers, with an unrivalled global reach and impact, Matthew is a highly sought-after international keynote speaker, lecturer, and mentor who collaborates with global leaders through the United Nations Alliance of Civilizations (UNAOC) and United Nations General Assembly (UNGA) to shape pivotal initiatives such as the UN’s AI for Humanity program, the United Nations Conference of the Parties (UN COP), and the World Economic Forum in Davos.
As the former Global Head of Cloud, National Security, and Enterprise Sales for companies including Atos, Dell-EMC, and IBM, Matthew has a proven track record of building multi-billion dollar business units and turning failing divisions into market leaders. His ability to identify, analyse, and communicate the implications of hundreds of emerging technologies and trends is unparalleled, and his insights are trusted by many of the world’s most respected organisations, including ABB, Accenture, Adidas, AON, ARM, BCG, Centrica, Citi, Coca-Cola, Dentons, Deloitte, Dow Jones, EY, Google, KPMG, Lego, Legal & General, LinkedIn, Microsoft, PepsiCo, Qualcomm, RWE, Samsung, Siemens AG and Siemens Energy, T-Mobile, UBS, VISA, Walmart, Workday, Worldpay and many others.
Regularly featured in the global media including the AP, BBC, Bloomberg, CNBC, Discovery, Forbes, Khaleej Times, Telegraph, TIME, ViacomCBS, WIRED, and the WSJ, Matthews mission is to help organisations create a fair and sustainable future whose benefits are shared by everyone irrespective of their ability, background, or circumstances.
What future do you need to see?
Choose one to get started on security and privacy and the future of your organisation.
Sources and further reading
- The pumpkin eclipse blog.lumen.com
- OpenCVE for ActionTec opencve.io
- Hundreds of thousands of us internet routers destroyed in newly discovered 2023 hack kelo.com
- Chalubo botnet wants to ddos from your server or iot device news.sophos.com
- China's Volt Typhoon theregister.com
- AcidRain wiper case darkreading.com
Source: first published by the 311 Institute on 15 July 2024. Cite as: Griffin, M. (2024). Mystery hacking group bricked 600,000 modems in the US. 311 Institute. https://www.311institute.com/mystery-hacking-group-bricked-600000-modems-in-the-us/
You are welcome to quote this article with credit and a link to the original.