CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Milesight Routers Exploited in European Smishing Campaign

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Unknown threat actors have been exploiting Milesight industrial cellular routers to send phishing SMS messages targeting users in European countries since at least February 2022. The campaign primarily targets Sweden, Italy, and Belgium, using typosquatted URLs that impersonate government platforms and various service providers. The attackers exploit an API vulnerability in the routers to send malicious SMS messages, with no evidence of backdoors or further exploitation on the devices. The vulnerability has been actively exploited to disseminate smishing campaigns, with about 572 of the 18,000 accessible routers potentially vulnerable. The attacks involve an initial validation phase to verify the router's SMS capabilities. The phishing URLs include JavaScript to check for mobile access and disable analysis tools.

Timeline

  1. 01.10.2025 14:07 1 articles · 11h ago

    Smishing Campaign Targeting European Users via Milesight Routers Identified

    Unknown threat actors have been exploiting Milesight industrial cellular routers to send phishing SMS messages targeting users in European countries since at least February 2022. The campaign primarily targets Sweden, Italy, and Belgium, using typosquatted URLs that impersonate government platforms and various service providers. The attackers exploit an API vulnerability in the routers to send malicious SMS messages, with no evidence of backdoors or further exploitation on the devices. The phishing URLs include JavaScript to check for mobile access and disable analysis tools.

    Show sources

Information Snippets