Scammers have been abusing unsecured cellular routers used in industrial settings to blast SMS-based phishing messages in campaigns that have been ongoing since 2023, researchers said. The routers, manufactured by China-based Milesight IoT Co., Ltd., are rugged Internet of Things devices that use cellular networks to connect traffic lights, electric power meters, and other sorts of remote industrial devices to central hubs. They come equipped with SIM cards that work with 3G/4G/5G cellular networks and can be controlled by text message, Python scripts, and web interfaces. An unsophisticated, yet effective, delivery vector Security company Sekoia on Tuesday said that an analysis of “suspicious network traces” detected in its honeypots led to the discovery of a cellular router being abused to send SMS messages with phishing URLs. As company researchers investigated further, they identified more than 18,000 such routers accessible on the Internet, with at least 572 of them allowing free access to programming interfaces to anyone who took the time to look for them. The vast majority of the routers were running firmware versions that were more than three years out of date and had known vulnerabilities.Read full article Comments
That annoying SMS phish you just got may have come from a box like this

Advertisement
Related Articles
Blender 4.5 brings big changes
Article URL: https://lwn.net/Articles/1036262/ Comments URL: https://news.ycombinator.com/item?id=45458791 Points: 24 # Comments: 1
Rescuer at Fatal Tesla Cybertruck Crash Says Car …
Article URL: https://www.newsweek.com/tesla-cybertruck-car-door-malfunction-2043976 Comments URL: https://news.ycombinator.com/item?id=45458768 Points: 16 # Comments: 5
You Want Technology with Warts
Article URL: https://entropicthoughts.com/you-want-technology-with-warts Comments URL: https://news.ycombinator.com/item?id=45458550 Points: 5 # Comments: 0
Stdlib: A library of frameworks, templates, and guides …
Article URL: https://debuggingleadership.com/stdlib Comments URL: https://news.ycombinator.com/item?id=45458249 Points: 11 # Comments: 1
FyneDesk: A full desktop environment for Linux written …
Article URL: https://github.com/FyshOS/fynedesk Comments URL: https://news.ycombinator.com/item?id=45458122 Points: 17 # Comments: 2
Apple pulls ICEBlock from the App Store
Apple has removed the “Waze but for ICE sightings” app ICEBlock from its App Store, …