Malicious actors are exploiting Milesight industrial cellular routers to send SMS messages as part of a smishing targeting users in European countries. The campaign has been active since at least February 2022.

French cybersecurity firm SEKOIA reported that attackers are exploiting the cellular router API to send malicious SMS messages containing phishing URLs. The campaigns are mainly targeting Sweden, Italy and Belgium, using URLs that resemble government platforms as well as banking, postal and telecommunications providers.
Exploiting Milesight routers
Of the 18,000 routers of this type that are accessible on the public internet, at least 572 are estimated to be vulnerable due to the exposure of inbox/outbox APIs. About half of the identified vulnerable routers are located in Europe.
See also: RAM Battering Attack Bypasses Intel and AMD Security
SEKOIA stated: “In addition, the API allows for the retrieval of both incoming and outgoing SMS messages, indicating that the vulnerability has been actively exploited to spread malicious SMS campaigns since at least February 2022. There is no evidence of any attempt to install a backdoor or exploit other vulnerabilities on the device. This suggests a targeted approach, aligned specifically with the attacker’s smishing operations.”

The attackers are believed to be exploiting a (now) patched information disclosure vulnerabilityaffecting Milesight routers (CVE-2023-43261, CVSS score: 7.5). This vulnerability was discovered by security researcher Bipin Jitiya exactly two years ago. A few weeks later, VulnCheck revealed that the vulnerability may have been used in attacks (shortly after the public disclosure).
Further investigation revealed that some of the industrial routers expose SMS-related functions, such as sending messages or viewing SMS history, without requiring any form of authentication.
See also: MatrixPDF: New kit turns PDFs into phishing and malware baits
The attacks likely involve an initial validation phase, where malicious actors attempt to verify whether a particular router can send SMS messages targeting a phone number under their control. SEKOIA further noted that the API could also be publicly accessible due to misconfigurations, as some routers have been found to be running newer software versions that are not vulnerable to CVE-2023-43261.
Phishing URLs distributed using this method include JavaScript that checks if the page is being accessed by a mobile device before delivering the malicious content, which prompts users to update their banking information for a supposed refund.
Additionally, one of the domains used in the campaigns between January and April 2025 – jnsi[.]xyz – includes JavaScript code to disable right-click actions and browser debuggers (in an attempt to thwart analysis efforts). Some of the pages have also been found to log visitors’ connections to a Telegram bot called GroozaBot , which is operated by an agent named “ Gro_oza ,” who appears to speak both Arabic and French.
See also: Android banking trojan uses VNC server to remotely control devices

SEKOIA concluded: “The smishing campaigns appear to have been conducted through the exploitation of vulnerable cellular routers – a relatively simple, yet effective, delivery method. These devices are particularly attractive to malicious actors as they allow for decentralized SMS distribution across multiple countries, making both detection and takedown efforts difficult.”
The exploitation of industrial IoT devices for mass smishing highlights a shift in strategy: instead of directly targeting user networks, attackers are adopting “delivery platforms” — easily customizable — that multiply the reach of attacks and obscure the origin. For organizations, this means that security must extend beyond endpoints: isolating the management plane of routers, disabling non-essential APIs, enforcing strong access , and regularly auditing settings. At the same time, mobile providers and SIEM platforms must integrate detection rules for unusual SMS patterns and outbound flows. Finally, enterprises must inform staff and customers about smishing techniques and implement procedures for rapid recall and isolation of infected devices.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
