Australian drone firm CubePilot has reported a major operational disruption following a DNS hijacking attack that allowed hackers to intercept traffic and potentially steal user credentials via fraudulent TLS certificates.

Key Takeaways

  • Attackers hijacked the cubepilot.org DNS settings on July 24.
  • Fraudulent TLS certificates were obtained, making the attack look legitimate via HTTPS.
  • Users are urged to change passwords used on July 24 immediately.
  • All OEM services, forums, and the ERP portal are currently offline as a precaution.

CubePilot, a leading Australian designer of flight controllers for Unmanned Aerial Vehicles (UAVs), has announced it fell victim to a sophisticated DNS hijacking attack. By manipulating the Domain Name System records, threat actors successfully redirected legitimate traffic to their own infrastructure, exposing users to potential data interception and phishing.

The breach reached a critical level when attackers managed to obtain TLS certificates covering all cubepilot.org subdomains. This allowed the attackers to present valid HTTPS connections to unsuspecting users, making the malicious sites appear completely secure and authentic. This level of deception makes it incredibly difficult for even seasoned users to detect the interception.

Why This Matters

BozokMedia analysis shows that DNS hijacking represents one of the most insidious forms of cyberattacks because it undermines the very foundation of internet trust. When attackers control the DNS and possess valid certificates, they bypass the primary layer of defense that most users and automated systems rely on to verify identity and encryption.

When attackers control both the DNS and the TLS certificates, the distinction between a legitimate service and a malicious one virtually disappears for the end-user.

In response to the incident, CubePilot has taken several emergency measures. CEO Philip Rowse confirmed that the company's ERP portal and community forums have been taken offline to prevent further compromise. The company is also working closely with the Australian Cyber Security Centre and law enforcement to investigate the full extent of the breach.

Historical Context

CubePilot is a critical player in the UAV ecosystem, providing navigation hardware for industries ranging from agriculture and search-and-rescue to defense and government operations. Notably, the company has been a vocal supporter of Ukraine, providing drone technology as part of international assistance packages, which underscores the high-stakes nature of their security environment.

Did You Know?: DNS hijacking can be used to facilitate 'Man-in-the-Middle' attacks, where an attacker sits invisibly between you and the website you think you are visiting.

Frequently Asked Questions

1. Is my firmware safe to use?
Firmware obtained before July 24 is considered safe. Avoid flashing any images downloaded on July 24-25 until further notice.

2. What should I do if I entered my credentials during the attack?
Change your passwords immediately, especially if you reuse the same password on other platforms.