Categories USA News

That annoying SMS phish you just got may have come from a box like this

Scammers have been abusing unsecured cellular routers used in industrial settings to blast SMS-based phishing messages in campaigns that have been ongoing since 2023, researchers said.

The routers, manufactured by China-based Milesight IoT Co., Ltd., are rugged Internet of Things devices that use cellular networks to connect traffic lights, electric power meters, and other sorts of remote industrial devices to central hubs. They come equipped with SIM cards that work with 3G/4G/5G cellular networks and can be controlled by text message, Python scripts, and web interfaces.

An unsophisticated, yet effective, delivery vector

Security company Sekoia on Tuesday said that an analysis of “suspicious network traces” detected in its honeypots led to the discovery of a cellular router being abused to send SMS messages with phishing URLs. As company researchers investigated further, they identified more than 18,000 such routers accessible on the Internet, with at least 572 of them allowing free access to programming interfaces to anyone who took the time to look for them. The vast majority of the routers were running firmware versions that were more than three years out of date and had known vulnerabilities.

Read full article

Comments

More From Author

You May Also Like

In these difficult times, Farragut’s Public League title in 16-inch softball is source of pride

Operation Midway Blitz, the federal immigration crackdown that began in September, has disrupted daily life…

‘Yo tengo papeles’: Teacher detained by immigration agents in North Center day care

Federal immigration agents entered a North Center day care and arrested a teacher Wednesday before…

“You must be held accountable”: Mamdani gears up for ICE showdown

Zohran Mamdani sent a message to Immigration and Customs Enforcement agents mere hours after handily…