CubePilot Drone Software Developer Hit by Sophisticated DNS Hijacking Attack
A severe operational disruption has hit CubePilot, an Australian company that designs flight controllers for drones (UAVs), after a sophisticated cyberattack allowed attackers to intercept traffic intended for internal systems. The attack involved hijacking the company’s domain name system (DNS) records, allowing threat actors to redirect users to their own infrastructure and exposing sensitive data to interception.
The attacker gained control of CubePilot’s cubepilot[.]org domain DNS settings on July 24, enabling them to intercept traffic intended for internal systems. To add an extra layer of deception, the attackers also obtained Transport Layer Security (TLS) certificates covering all cubepilot.org subdomains. This meant that users visiting affected services would have seen valid HTTPS connections while unknowingly landing on attacker-controlled infrastructure.
As a result, CubePilot warned its users to change their passwords immediately and advised those who reused their login credentials elsewhere to update them as well. The company has since regained control of its domains and revoked the fraudulently issued certificates. It has also notified relevant providers, reported the incident to the Australian Cyber Security Centre and law enforcement, and promised to notify affected entities directly where impact is confirmed through its investigation.
CubePilot’s products are used in various industries, including surveying, search and rescue, agriculture, and defense and government applications. The company had previously announced its support for Ukraine and had delivered its products to the country as part of an Australian government assistance package. Currently, all OEM services, community forum, and documentation portal are offline due to the attack.
The incident highlights the importance of robust cybersecurity measures in protecting sensitive data and preventing disruptions to critical infrastructure. As CubePilot’s CEO, Philip Rowse, noted on LinkedIn, the company is taking a precautionary approach by temporarily taking its ERP portal offline while an investigation into the incident is underway. Users are advised not to flash images downloaded on July 24-25 until checks confirm their safety.
In light of this attack, it’s essential for organizations and individuals to remain vigilant and regularly test their security measures. This includes evaluating the integrity of published firmware images, verifying the authenticity of payment requests, and implementing robust cybersecurity protocols to prevent similar attacks in the future. By taking proactive steps to secure their systems and data, users can reduce the risk of falling victim to such sophisticated cyberattacks.
Source: Bleeping Computer — 2026-07-28