CubePilot says a DNS hijacking attack caused severe disruption after an attacker gained control of the domain settings for cubepilot.org. The incident allowed the threat actor to redirect and intercept traffic intended for the Australian drone technology company’s internal systems.

The attacker also obtained valid TLS certificates for all CubePilot subdomains. As a result, affected users may have connected to attacker-controlled services through what appeared to be legitimate HTTPS connections.

Attacker controlled CubePilot DNS settings

CubePilot said the attack began on 24 July, when an unauthorised party took control of the DNS configuration for cubepilot.org.

DNS records direct users to the correct online service. If attackers hijack those records, they can redirect visitors to infrastructure under their own control.

This can enable credential theft, phishing, malware delivery and the interception of sensitive data. In this case, CubePilot warned that credentials entered into its portal or forum on 24 July may have been captured.

The company urged users who reused passwords elsewhere to change those passwords immediately.

Fraudulent TLS certificates made affected services appear legitimate

The attacker obtained TLS certificates covering every cubepilot.org subdomain, CubePilot said.

TLS certificates normally secure HTTPS connections and help browsers verify that a website is authentic. However, attackers with control over a domain’s DNS settings can sometimes obtain valid certificates for that domain.

This means users could have seen a valid HTTPS connection while unknowingly reaching attacker-controlled infrastructure.

CubePilot said it regained control of its domains on 24 July and revoked the fraudulently issued certificates. It has also preserved evidence, notified relevant providers and reported the incident to the Australian Cyber Security Centre and law enforcement.

CubePilot takes services offline during investigation

Several CubePilot services are currently offline while the company investigates the breach. These include OEM services, the community forum and the documentation portal.

CubePilot CEO Philip Rowse said the company also took its ERP portal offline as a precaution.

The firm designs flight controllers, navigation hardware and autopilot systems for drones. Its products are used in areas including surveying, agriculture, search and rescue, defence and government operations.

CubePilot said it will contact affected organisations directly where its investigation confirms an impact.

Customers warned about firmware and payment requests

CubePilot is reviewing the integrity of firmware images published during the incident. Customers have been advised not to install firmware downloaded on 24 or 25 July until the company completes safety checks.

Firmware downloaded before 24 July is currently considered safe to use.

The company also warned customers to treat unexpected payment requests with caution. Anyone receiving a request that appears to come from CubePilot should confirm it by phone with their usual company contact before taking action.


0 responses to “CubePilot DNS Hijacking Attack Intercepted User Traffic”