That annoying SMS phish you just got may have come from a box like this

That annoying SMS phish you just got may have come from a box like this

Scammers have found a new tool in their arsenal: unsecured cellular routers commonly used in industrial applications. Research indicates that since early 2023, these devices have been exploited to launch widespread SMS phishing campaigns. Manufactured by Milesight IoT Co., Ltd., a company based in China, these rugged Internet of Things (IoT) routers serve as crucial links for connecting essential infrastructure like traffic lights and power meters to centralized systems. Equipped with SIM cards compatible with 3G, 4G, and 5G networks, these routers can be managed through text messaging, Python scripts, and web interfaces. A report from security firm Sekoia revealed that an analysis of suspicious network activity captured in their honeypots uncovered instances of these routers being misused to send out SMS messages embedded with phishing links. Upon further investigation, researchers discovered over 18,000 of these routers were publicly accessible on the internet. Alarmingly, at least 572 of them had unprotected programming interfaces, making them easy targets for cybercriminals. Many of these devices were running outdated firmware—some by more than three years—and contained known security vulnerabilities. By sending requests to these unauthenticated APIs, researchers were able to access the SMS inbox and outbox of the routers. The findings revealed a series of smishing campaigns that commenced in October 2023, targeting phone numbers across various countries, notably Sweden, Belgium, and Italy. The fraudulent messages typically directed recipients to log into accounts related to government services, aiming to steal personal credentials through deceptive links. According to Sekoia's researchers, Jeremy Scion and Marc N., these phishing campaigns illustrate a concerning trend. They noted that the exploitation of vulnerable cellular routers represents a relatively simple yet effective method for distributing phishing messages globally. The decentralized nature of these devices complicates the efforts to detect and dismantle such scams, posing a significant challenge to cybersecurity initiatives.

Sources : Ars Technica

Published On : Oct 01, 2025, 22:20

Streaming
Amazon Unveils Price Increase for Ad-Free Prime Video with New Features

Amazon has announced a $2 increase in the monthly fee for its ad-free Prime Video service in the U.S., raising it from $...

CNBC | Mar 13, 2026, 16:35
Amazon Unveils Price Increase for Ad-Free Prime Video with New Features
Streaming
Spotify Introduces Customizable Taste Profiles for Enhanced Music Recommendations

At the recent SXSW conference, Spotify co-CEO Gustav Söderström unveiled an exciting new feature designed to give listen...

TechCrunch | Mar 13, 2026, 17:35
Spotify Introduces Customizable Taste Profiles for Enhanced Music Recommendations
AI
Elon Musk Announces Major Overhaul of xAI Following Co-Founder Departures

In a surprising turn of events, Elon Musk has revealed that his artificial intelligence venture, xAI, is undergoing a si...

CNBC | Mar 13, 2026, 18:45
Elon Musk Announces Major Overhaul of xAI Following Co-Founder Departures
AI
Job Market Alarm: AI's Impact on New Graduates Could Push Unemployment Rates to Shocking Heights

The rise of artificial intelligence is poised to create significant challenges for recent college graduates as companies...

CNBC | Mar 13, 2026, 16:15
Job Market Alarm: AI's Impact on New Graduates Could Push Unemployment Rates to Shocking Heights
Automotive
Revolutionizing Electric Vehicles: The Impact of 800V Architecture

For years, the majority of electric vehicles (EVs) have relied on a standard battery pack operating at approximately 400...

Ars Technica | Mar 13, 2026, 18:35
Revolutionizing Electric Vehicles: The Impact of 800V Architecture
View All News