Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

BeyondTrust fixes critical pre-authentication RCE vulnerability in remote support and PRA

Working together to build the fusion energy supply chain of the future

Well, I’m a little less angry about the “Magnificent Ambersons” AI project

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Hackers abuse Miles routers to send phishing SMS to European users
Identity

Hackers abuse Miles routers to send phishing SMS to European users

userBy userOctober 1, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 1, 2025Ravi LakshmananVulnerability/Malware

Unknown threat actors have abused the Milesight Industrial Cellular Router since at least February 2022 to send SMS messages as part of an SMS campaign targeting users in European countries.

French cybersecurity firm Sekoia said attackers are leveraging Cellular Router’s API to send malicious SMS messages containing phishing URLs, and campaigns that target mainly Sweden, Italy and Belgium target Typosted URLs that decorate government platforms such as CSAM and EBox, as well as government platforms such as banks and post offices.

Of the 18,000 routers of this type that can be accessed on the public Internet, over 572 have been rated potentially vulnerable as they expose their inbox/outbox APIs. Approximately half of the vulnerable routers identified are in Europe.

DFIR Retainer Service

“In addition, the API allows for the retrieval of both incoming and outgoing SMS messages, indicating that the vulnerability has been actively exploited in malicious SMS campaigns since at least February 2022,” the company said. “There is no evidence of attempts to install backdoors or leverage other vulnerabilities on the device. This suggests a targeting approach specialized for attacker smishing operations.”

The attacker is believed to be exploiting the current flaws in disclosure affecting miles routers (CVE-2023-43261, CVSS score: 7.5). A few weeks later, Vulncheck revealed that the vulnerability could have been weaponized in the wild shortly after its release.

Further investigations revealed that some industrial routers expose SMS-related features without the need for authentication in any form, such as sending messages or displaying SMS history.

An attack could include an initial verification phase in which a threat actor attempts to verify whether a particular router can send SMS messages by targeting a phone number under his control. Sekoia further noted that since several routers are known to be running recent firmware versions that are less susceptible to CVE-2023-43261, the API could also be exposed due to false guiding.

Phishing URLs distributed using this method include JavaScript that checks whether the page is being accessed from a mobile device before serving malicious content.

CIS Build Kit

Additionally, one of the domains used in the campaign between January and April 2025 – JNSI[.]XYZ – Make JavaScript code work that disables right-click actions and browser debugging tools to prevent analysis efforts. Some pages are also known to record visitor connections to a telegram bot named Groozabot, run by an actor named “gro_oza”, who appears to speak both Arabic and French.

“The vulnerable campaign appears to have been carried out through the use of vulnerable cell routers. This is a relatively unsleek but effective delivery vector,” Sequoia said. “These devices are particularly appealing to threat actors as they allow for decentralized SMS distribution across multiple countries and complicate both detection and takedown efforts.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHidden violations, attack surface growth, and AI misconceptions rise
Next Article “Midnight” Evtol destroys its own records with the latest test flights.
user
  • Website

Related Posts

BeyondTrust fixes critical pre-authentication RCE vulnerability in remote support and PRA

February 9, 2026

OpenClaw integrates VirusTotal scanning to detect malicious ClawHub skills

February 8, 2026

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

February 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

BeyondTrust fixes critical pre-authentication RCE vulnerability in remote support and PRA

Working together to build the fusion energy supply chain of the future

Well, I’m a little less angry about the “Magnificent Ambersons” AI project

Dozens of people march in support of billionaire in San Francisco

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.