By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

GadgetBond

  • Latest
  • How-to
  • Tech
    • AI
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Add GadgetBond as a preferred source to see more of our stories on Google.
Font ResizerAa
GadgetBondGadgetBond
  • Latest
  • Tech
  • AI
  • Deals
  • How-to
  • Apps
  • Mobile
  • Gaming
  • Streaming
  • Transportation
Search
  • Latest
  • Deals
  • How-to
  • Tech
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • AI
    • Anthropic
    • ChatGPT
    • ChatGPT Atlas
    • Gemini AI (formerly Bard)
    • Google DeepMind
    • Grok AI
    • Meta AI
    • Microsoft Copilot
    • OpenAI
    • Perplexity
    • xAI
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Follow US
NewsSecurityTech

Massive internet outage: 600,000 routers bricked in 3 days

Windstream customers were left without internet after over 600,000 routers were permanently disabled by malicious firmware in a coordinated cyberattack deploying the Chalubo malware.

By
Shubham Sawarkar
Shubham Sawarkar's avatar
ByShubham Sawarkar
Editor-in-Chief
I’m a tech enthusiast who loves exploring gadgets, trends, and innovations. With certifications in CISCO Routing & Switching and Windows Server Administration, I bring a sharp...
Follow:
- Editor-in-Chief
Jun 2, 2024, 1:30 PM EDT
Share
We may get a commission from retail offers. Learn more
A close-up photo of a black router with three antennas. The router is blinking red light. In the background, there is a solid blue background.
Illustration by Rengised / Dribbble
SHARE

In a shocking incident, an unidentified hacker has crippled hundreds of thousands of home internet routers in a coordinated attack. Over a mere 72-hour period in October 2023, a malicious firmware update effectively bricked more than 600,000 routers belonging to a single internet service provider (ISP). This left countless homes and businesses without internet access, causing significant disruption.

The attack targeted a specific model of router, the ActionTec T3200, primarily used for small offices and home offices (SOHO). Security researchers from Black Lotus Labs at Lumen Technologies meticulously analyzed the event, detailing it in a recent report. Their findings paint a disturbing picture of a deliberate attempt to cause widespread internet outages.

The culprit behind this large-scale disruption appears to be a remote access trojan (RAT) called Chalubo. First identified in 2018, Chalubo is known for its ability to deliver customized malicious payloads specifically designed to compromise SOHO routers and Internet of Things (IoT) devices. In this instance, Chalubo was used to inject a corrupted firmware update onto the targeted routers.

Firmware is the underlying software that controls a device’s core functionality. A malicious update can essentially rewrite this code, rendering the device unusable. Security researchers believe the attackers used Chalubo to obfuscate their identity, opting for a common malware strain rather than a custom-developed tool.

While the attack method is becoming clearer, the motive behind this large-scale disruption remains shrouded in secrecy. Black Lotus Labs found no evidence linking the attack to known nation-state hacking groups. However, the researchers are confident this was a deliberate act of sabotage, aiming to create a denial-of-service (DoS) event – essentially, an internet blackout for the affected users.

Though the Black Lotus Labs report refrains from naming the affected ISP, Ars Technica has identified it as Windstream. This conclusion is based on details gleaned from Windstream subscribers’ reports during the October 2023 timeframe, along with the specific router model targeted in the attack.


Discover more from GadgetBond

Subscribe to get the latest posts sent to your email.

Most Popular

Kindle Colorsoft hits rare $170 pricing with 32% discount in spring sale

Kindle Scribe is nearly 40% off in Amazon’s Big Spring Sale

iOS 26.4 adds Ambient Music widget and chatbot support to CarPlay

Apple tvOS 26.4 rolls out Genius Browse, better audio, and subtitles

OpenAI and Handshake launch Codex Creator Challenge for students

Also Read
A person works at a wooden desk using a sleek white ASUS ExpertCenter P600 AiO desktop computer displaying colorful 3D landscape graphics, with pens and papers in the foreground and a softly lit home office in the background.

ASUS ExpertCenter P600 AiO puts AMD Ryzen AI on your desk

ASUS ExpertBook B3 G1 laptop in gentle grey, shown open at an angle with a thin-bezel display, full-size keyboard with number pad, large touchpad, and matching closed lid in the background.

ASUS ExpertBook B3 G1 debuts as AI-ready business laptop

Health and wellness icons showing a runner, medical clipboard with heart, and stethoscope in green, red, and blue.

Apple now makes the medical device status clear on App Store health apps

MLB Scout Insights dashboard showing baseball game analysis with player statistics, pitch location grid overlay, and team scoring information for Twins vs Red Sox.

MLB Scout Insights brings AI-powered context to every at-bat

Gemini logo surrounded by translucent glass chat bubbles on a light background for Play Store promotion.

Google Gemini can now import chats from other AI apps

MedGemma logo with 'Med' in black and 'Gemma' in blue gradient text.

Google’s MedGemma Challenge crowns EpiCast as global winner

Smartphone showing Google Translate live translation mode options including Listening, Conversation, Text only, and Custom settings, with a Start button.

Live Translate with headphones finally lands on iOS for real-time conversations

Build with Gemini 3.1 Flash Live logo on dark background with colorful Gemini star icon and blue pixelated hand illustration with gradient dot trail.

Gemini 3.1 Flash Live brings multilingual, low-latency AI to developers

Company Info
  • Homepage
  • Support my work
  • Latest stories
  • Company updates
  • GDB Recommends
  • Daily newsletters
  • About us
  • Contact us
  • Write for us
  • Editorial guidelines
Legal
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • DMCA
  • Disclaimer
  • Accessibility Policy
  • Security Policy
  • Do Not Sell or Share My Personal Information
Socials
Follow US

Disclosure: We love the products we feature and hope you’ll love them too. If you purchase through a link on our site, we may receive compensation at no additional cost to you. Read our ethics statement. Please note that pricing and availability are subject to change.

Copyright © 2026 GadgetBond. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | Do Not Sell/Share My Personal Information.