CubePilot Drone Autopilot Vendor Hit by DNS Hijacking, Enabling Traffic Interception and Fraudulent TLS Certificates — Threadlinqs Intelligence
As of 2026-07-28, CubePilot Drone Autopilot Vendor Hit by DNS Hijacking, Enabling Traffic Interception and Fraudulent TLS Certificates is a high-severity supply chain threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1749 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
On July 24, 2026, an unattributed attacker seized DNS control of cubepilot.org, obtained fraudulent TLS certificates covering all subdomains, and intercepted traffic to the OEM portal, community
CubePilot Global Pty Ltd, a Geelong, Australia-based manufacturer of drone flight-controller hardware (the Cube autopilot family) whose products sit on the US Department of Defense's Blue UAS cleared list through 2027, disclosed that an attacker gained control of the DNS settings for its primary domain, cubepilot.org, on July 24, 2026. Because DNS control determines which certificate authority domain-validation challenges resolve against, the attacker was able to obtain valid, fraudulently-issued TLS certificates covering every cubepilot.org subdomain. This let the attacker present browser-trusted HTTPS connections while redirecting visitors of CubePilot's OEM portal, community/support forum, documentation site, and ERP portal to attacker-controlled infrastructure — a domain-hijack-enabled adversary-in-the-middle position rather than a vulnerability in any CubePilot product.
CubePilot states that any credentials entered on its services on July 24, including the OEM portal and forum, may have been captured, and has urged affected users to rotate reused passwords. Because the compromise briefly sat astride CubePilot's software/firmware distribution channel, the company additionally flagged firmware images downloaded between July 24 and July 25, 2026 as not yet confirmed safe, while firmware obtained before July 24 is considered unaffected. CubePilot also warned customers that any payment request purporting to come from the company should be verified by phone before acting on it, anticipating possible follow-on business-email-compromise-style fraud using data or trust harvested during the compromise window.
CubePilot's response, per its public statement and CEO Philip Rowse, included regaining domain control same-day, revoking the fraudulent certificates, preserving evidence, notifying affected providers, taking the OEM portal, forum, documentation site, and ERP portal offline as a precaution, and reporting the incident to the Australian Cyber Security Centre (ACSC) and law enforcement. As of disclosure, no CVE, malware sample, attacker infrastructure (IPs/domains), or attribution had been published; the incident is a vendor-infrastructure/DNS-and-PKI-trust compromise rather than a code-level vulnerability, but it is supply-chain relevant because CubePilot's Cube autopilot hardware and ArduPilot/PX4-compatible firmware are widely used across defense, government, agriculture, surveying, and search-and-rescue drone deployments, including under the AUKUS-aligned Blue UAS program.
Target sectors: defense, government administration, agriculture, critical-infrastructure, technology-manufacturing
Target regions: australia, North America, Global
Detections & IOCs
As of 2026-08-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1590, T1583, T1584, T1588, T1199, T1195, T1656, T1584, T1608, T1036