Pink Botnet
Summary
According to the findings of the researchers, the Pink Botnet, at its peak, had infected and asserted control over more than 1.6 million devices. The botnet is backed by a complex and robust architecture that allows the attackers to exert complete control over the breached devices. The particular capabilities of the Pink botnet allow it to flash the original firmware of the breached fiber router and then rewrite it with a new one that includes a C2 downloader and the accompanying bootloader. This allowed them to retain their illegal access to the infected routers successfully, while also defending against several different approaches from the devices vendor. In the end, the vendor had to resort to sending dedicated technicians to access the breached routers and either disassemble the debugging software or replace the unit altogether.