Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • KV Cache Is Eating Your VRAM. Here’s How Google Fixed It With TurboQuant.
    • OneOdio Focus A1 Pro review
    • The 11 Best Fans to Buy Before It Gets Hot Again (2026)
    • A look at Dylan Patel’s SemiAnalysis, an AI newsletter and research firm that expects $100M+ in 2026 revenue from subscriptions and AI supply chain research (Abram Brown/The Information)
    • ‘Euphoria’ Season 3 Release Schedule: When Does Episode 2 Come Out?
    • Francis Bacon and the Scientific Method
    • Proxy-Pointer RAG: Structure Meets Scale at 100% Accuracy with Smarter Retrieval
    • Sulfur lava exoplanet L 98-59 d defies classification
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Sunday, April 19
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»That annoying SMS phish you just got may have come from a box like this
    News

    That annoying SMS phish you just got may have come from a box like this

    Editor Times FeaturedBy Editor Times FeaturedOctober 2, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    The researchers added: “This marketing campaign is notable in that it demonstrates how impactful smishing operations could be executed utilizing easy, accessible infrastructure. Given the strategic utility of such tools, it’s extremely possible that related units are already being exploited in ongoing or future smishing campaigns.”

    Sekoia stated it’s unclear how the units are being compromised. One chance is thru CVE-2023-43261, a vulnerability within the routers that was mounted in 2023 with the discharge of model 35.3.0.7 of the machine firmware. The overwhelming majority of 572 recognized as unsecured ran variations 32 or earlier.

    CVE-2023-43261 stemmed from a misconfiguration that made information in a router’s storage publicly out there by means of an online interface, in line with a post printed by Bipin Jitiya, the researcher who found the vulnerability. Amongst different issues, among the information contained cryptographically protected passwords for accounts, together with the machine administrator. Whereas the password was encrypted, the file additionally included the key encryption key used and an IV (initialization vector), permitting an attacker to acquire the plaintext password after which acquire full administrative entry.

    The researchers stated that this principle was contradicted by among the details uncovered of their investigation. For one, an authentication cookie discovered on one of many hacked routers used within the marketing campaign “couldn’t be decrypted utilizing the important thing and IV described within the article,” the researchers wrote, with out elaborating additional. Additional, among the routers abused within the campaigns ran firmware variations that weren’t inclined to CVE-2023-43261.

    Milesight did not reply to a message in search of remark.

    The phishing web sites ran JavaScript that prevented pages from delivering malicious content material except it was accessed from a cellular machine. One website additionally ran JavaScript to disable right-click actions and browser debugging instruments. Each strikes have been possible made in an try and hinder evaluation and reverse engineering. Sekoia additionally discovered that among the websites logged customer interactions by means of a Telegram bot often called GroozaBot. The bot is thought to be operated by an actor named “Gro_oza,” who seems to talk each Arabic and French.

    Given the prevalence and big quantity of smishing messages, folks usually marvel how scammers handle to ship billions of messages per 30 days with out getting caught or shut down. Sekoia’s investigation means that in lots of instances, the assets come from small, often-overlooked containers tucked away in janitorial closets in industrial settings.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    A look at Dylan Patel’s SemiAnalysis, an AI newsletter and research firm that expects $100M+ in 2026 revenue from subscriptions and AI supply chain research (Abram Brown/The Information)

    April 19, 2026

    Google is in talks with Marvell Technology to develop a memory processing unit that works alongside TPUs, and a new TPU for running AI models (Qianer Liu/The Information)

    April 19, 2026

    At the Beijing half-marathon, several humanoid robots beat human winners by 10+ minutes; a robot made by Honor beat the human world record held by Jacob Kiplimo (Reuters)

    April 19, 2026

    A look at the AI nonprofit METR, whose time-horizon metrics are used by AI researchers and Wall Street investors to track the rapid development of AI systems (Kevin Roose/New York Times)

    April 19, 2026

    Binance and Bitget to probe a rally in RaveDAO’s RAVE token, which surged 4,500% in a week, after ZachXBT alleged RAVE insiders engineered a large short squeeze (Francisco Rodrigues/CoinDesk)

    April 19, 2026

    Mistral, which once aimed for top open models, now leans on being an alternative to Chinese and US labs, says it’s on track for $80M in monthly revenue by Dec. (Iain Martin/Forbes)

    April 19, 2026

    Comments are closed.

    Editors Picks

    KV Cache Is Eating Your VRAM. Here’s How Google Fixed It With TurboQuant.

    April 19, 2026

    OneOdio Focus A1 Pro review

    April 19, 2026

    The 11 Best Fans to Buy Before It Gets Hot Again (2026)

    April 19, 2026

    A look at Dylan Patel’s SemiAnalysis, an AI newsletter and research firm that expects $100M+ in 2026 revenue from subscriptions and AI supply chain research (Abram Brown/The Information)

    April 19, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Premier League Soccer: Stream Bournemouth vs. Arsenal Live From Anywhere

    January 3, 2026

    Today’s NYT Mini Crossword Answers for Dec. 16

    December 16, 2025

    Illegal gambling FBI raid in Wilder sparks community outrage for ‘excessive force’

    October 21, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.