CubePilot drone software dev hit by DNS hijacking to intercept traffic
CubePilot, an Australian firm that designs flight controllers for drones, announced a severe operational disruption caused by a DNS hijacking attack. The attacker gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercept traffic inte…
Intelligence analysis by Llama

CubePilot's DNS hijacking incident exposed users to sensitive data interception, malware delivery, and phishing. The company regained control of its domains, revoked the fraudulently issued certificates, and notified relevant providers.
Imagine you're trying to visit a website, but the bad guys are tricking your computer into going to a fake website instead. This is what happened to CubePilot, a company that makes software for drones. The bad guys took control of CubePilot's website and could see all the information people were putting in, like passwords. Luckily, CubePilot was able to fix the problem and is now working to make sure it doesn't happen again.
Analysis
A Severe Operational Disruption
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. Hijacking domain name system (DNS) records allows threat actors to redirect users to their infrastructure, diverting traffic intended for a legitimate service. This exposes users to dangerous scenarios such as sensitive data interception, malware delivery, and phishing.
The Attack
According to a status update published on CubePilot’s website, an attacker gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercept traffic intended for internal systems. The attacker also obtained TLS certificates covering all cubepilot.org subdomains, meaning users visiting affected services would have seen valid HTTPS connections while unknowingly landing on attacker-controlled infrastructure.
The Impact
“The certificates obtained by the attacker covered every cubepilot.org subdomain, so credentials entered on any of our services on 24 July may have been captured — the portal and the forum included,” reads the announcement . “If you used the same password anywhere else, change it there now,” warned CubePilot. CubePilot said it regained control of its domains on July 24, revoked the fraudulently issued certificates, preserved evidence, notified relevant providers, and reported the incident to the Australian Cyber Security Centre and law enforcement. Also, the company promised to notify affected entities directly where impact is confirmed through its investigation.
The Company’s Response
CubePilot designs “autopilots” and navigation hardware for UAVs used in surveying, search and rescue, agriculture, and also defense and government applications. Previously, the company publicly announced its support for Ukraine , and its products have been delivered in the country, including as part of an Australian government assistance package. Currently, all OEM services, the community forum, and the documentation portal are offline. CubePilot’s CEO, Philip Rowse, stated on LinkedIn that the platform’s ERP portal has also been taken offline as a precaution while an investigation into the incident is underway. Regarding the integrity of the published firmware images, CubePilot is currently evaluating them and advised not to flash images downloaded on July 24-25 until checks to confirm their safety are completed. Firmware obtained before July 24 is currently considered safe to use. Finally, clients who receive payment requests claiming to be from CubePilot are advised not to take any action and instead to confirm them over the phone with their usual contact.
Key points
- CubePilot's DNS hijacking incident exposed users to sensitive data interception, malware delivery, and phishing.
- The attacker gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercept traffic intended for internal systems.
- CubePilot regained control of its domains, revoked the fraudulently issued certificates, and notified relevant providers.
- The company's ERP portal has been taken offline as a precaution while an investigation into the incident is underway.
- Firmware obtained before July 24 is currently considered safe to use.
CubePilot's swift response to the incident and its commitment to notifying affected entities directly may help to mitigate the damage. Additionally, the company's evaluation of the published firmware images and its advice to clients to confirm payment requests over the phone may help to prevent further issues.
The incident highlights the vulnerability of DNS systems to hijacking attacks, which can have severe consequences for users and organizations. If not properly addressed, this incident may lead to further security breaches and data losses.



