CubePilot Hit by DNS Hijacking Attack, Exposing User Credentials
Australian drone flight controller developer CubePilot suffered a DNS hijacking attack that allowed attackers to intercept traffic and potentially steal user credentials.

CubePilot, an Australian firm specializing in flight controllers for drones, has announced a significant disruption to its operations following a DNS hijacking attack. The incident, which occurred on July 24, saw attackers gain unauthorized control over the company's domain name system (DNS) records for cubepilot[.]org.
DNS hijacking is a malicious technique where attackers manipulate DNS records to redirect users attempting to access legitimate websites or services to their own controlled infrastructure. This redirection can lead to severe consequences, including the interception of sensitive data, the distribution of malware, and the execution of phishing attacks. In CubePilot's case, the attackers were able to divert traffic intended for the company's internal systems.
A particularly concerning aspect of the attack was the acquisition of TLS certificates that covered all cubepilot.org subdomains. This allowed the attackers to present seemingly legitimate HTTPS connections to users, even while redirecting them to malicious sites. Consequently, any credentials entered by users on CubePilot's services on July 24, including their portal and forum, may have been compromised.
CubePilot has urged its customers to change their passwords immediately, especially if they reused the same password on other platforms. The company stated that it regained control of its domains on the same day the attack occurred, July 24. Following the incident, CubePilot revoked the fraudulent TLS certificates, preserved evidence of the attack, notified relevant service providers, and reported the incident to both the Australian Cyber Security Centre and law enforcement agencies.
The company is currently investigating the full impact of the breach and plans to notify affected entities directly. As a precautionary measure, CubePilot has taken several of its services offline, including its OEM services, community forum, and documentation portal. The company's CEO, Philip Rowse, also confirmed on LinkedIn that the ERP portal has been taken offline.
CubePilot's products, which include autopilots and navigation hardware for UAVs, are used in various critical sectors such as surveying, search and rescue, agriculture, and defense. The company has previously announced its support for Ukraine, with its products being delivered to the country as part of Australian government assistance.
Regarding the integrity of its firmware, CubePilot is currently evaluating downloaded images from July 24-25 and advises customers not to flash them until their safety is confirmed. Firmware downloaded before July 24 is considered safe. Additionally, CubePilot has warned clients to be wary of any payment requests claiming to be from the company and to verify them via phone with their usual contact.
This incident highlights the persistent threat of supply chain attacks and the critical importance of securing DNS infrastructure. For organizations like CubePilot, whose products are used in sensitive applications, the compromise of their domain and the potential exfiltration of customer data can have far-reaching implications.