>samit_hota
Back to security news
SN-2026-219CriticalMitigated

CubePilot Disruption: Drone Software Developer Target of DNS Hijacking

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
CubePilot infrastructure, cubepilot.org services, UAV operators using CubePilot firmware
#news#phishing-social-engineering#cubepilot

Drone flight controller manufacturer CubePilot has suffered a severe operational disruption after attackers compromised the DNS settings for its primary domain, cubepilot.org. The Australian company, known for producing hardware and software navigation systems used in unmanned aerial vehicles (UAVs) across defense, agriculture, and search-and-rescue sectors, confirmed that malicious actors redirected incoming web traffic and generated legitimate TLS certificates for its subdomains on July 24.

The incident has forced CubePilot to take critical infrastructure offline—including its community forum, documentation portal, OEM services, and Enterprise Resource Planning (ERP) platform—while internal teams and law enforcement evaluate the full extent of the compromise.

How the DNS Hijack and Certificate Fraud Occurred

In a DNS hijacking attack, adversaries gain control over a victim’s domain name system records, typically through stolen domain registrar credentials, compromised management APIs, or social engineering targeting domain registrar support personnel. Once control is established, the attackers replace legitimate IP addresses in A/AAAA records with those of attacker-controlled infrastructure, seamlessly rerouting user traffic without triggering typical endpoint network alerts.

During the July 24 breach, the attackers leveraged their control over the cubepilot.org domain to pass Automated Certificate Management Environment (ACME) domain validation challenges—specifically using DNS-01 verification. By controlling the DNS TXT records required by Certificate Authorities, the threat actors successfully issued valid TLS certificates covering all cubepilot.org subdomains.

This allowed the attackers to terminate encrypted HTTPS sessions on their own servers without triggering browser warnings or security errors. Anyone visiting CubePilot portals or services during the attack window on July 24 would have observed a valid padlock icon and HTTPS connection, unaware that their session and input data were being intercepted by a man-in-the-middle (MITM) architecture.

Supply Chain Risks and Geopolitical Blast Radius

The compromise of a core flight control developer introduces substantial hardware and software supply chain risks. CubePilot’s hardware platforms and associated firmware underpin thousands of commercial and military UAV systems worldwide. The company has publicly supported Ukraine, delivering navigation hardware directly and through official Australian government military assistance packages.

Because drone platforms rely heavily on secure software pipelines for navigation parameter updates, waypoint mapping, and firmware flashing, hijacking an autopilot vendor’s web domain creates several severe threat vectors:

  • Credential Harvesting: Credentials entered into the CubePilot user portal or developer forums on July 24 were likely intercepted. If developers reuse these credentials across internal code repositories or Ground Control Station (GCS) deployments, adversaries could expand access into connected organizations.
  • Firmware Tampering & Malicious Distribution: If attackers manipulate web endpoints where operators download binary images, they can distribute backdoored firmware to target platforms. While CubePilot reports no confirmed firmware compromise yet, malicious flight control firmware could allow threat actors to cause physical loss of aircraft, alter flight boundaries, or extract telemetry data.
  • Financial Fraud and Social Engineering: By leveraging control of domain settings and internal system access, attackers frequently launch business email compromise (BEC) campaigns, sending fake invoices or redirected payment requests to enterprise and defense clients.

CubePilot CEO Philip Rowse confirmed that the company’s ERP platform was taken offline as a precaution to isolate financial and operational data while forensic investigators audit the environment.

Current Response and Remediation Guidance

CubePilot regained control of its domain DNS settings on July 24, revoked the fraudulently issued TLS certificates, and notified the Australian Cyber Security Centre (ACSC) alongside law enforcement. Systems remain offline while the company evaluates the safety of published files and internal databases.

Operators, developers, and organizations utilizing CubePilot hardware and software should immediately execute the following steps:

  • Password Resets: Anyone who logged into any cubepilot.org subdomain—including the developer forum or portal—on July 24 must immediately change their password. If that password was reused on ground control stations, repository accounts, or corporate networks, those accounts must be reset immediately as well.
  • Firmware Hold: Do not flash any CubePilot firmware images downloaded on July 24 or July 25 to aircraft. Firmware downloaded prior to July 24 is assessed as safe. Images downloaded during the window must be held until CubePilot completes integrity checks and provides verified cryptographic hashes.
  • Payment Request Verification: Out-of-band telephone verification is required for any payment requests or modified banking details originating from parties claiming to represent CubePilot.
  • Certificate Revocation Monitoring: Enterprise network administrators should update their local Certificate Revocation Lists (CRLs) and verify that OCSP stitching catches the revoked rogue certificates issued under cubepilot.org on July 24.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call