Threat actors have systematically exploited Milesight industrial cellular routers to conduct widespread smishing attacks targeting users in several European countries. Security researchers from Sekoia identified that the attackers leveraged a feature in these routers designed to send SMS alerts to administrators, which is commonly used in industrial settings to monitor remote equipment. The campaign has been ongoing undetected since at least February 2022, with a significant focus on Belgium between November 2022 and July 2025. Attackers exploited CVE-2023-43261, a vulnerability that allows leakage of system logs from Milesight routers. By accessing these logs, the attackers could extract and crack encrypted administrator passwords, enabling them to connect to the routers and abuse the SMS API to send phishing messages. In some cases, attackers did not even need to exploit the vulnerability, as at least 572 routers were found to have their SMS APIs exposed to the internet without authentication. The smishing messages impersonated a variety of trusted entities, including government platforms such as Belgium's CSAM and eBox, French banking and postal services, and Swedish and Danish telecommunications providers. The phishing messages typically contained links to malicious domains, some of which were registered through NameSilo and hosted by Podaon, a Lithuanian provider. The majority of the spam was sent to users in Sweden, Italy, and Belgium, with the intent to harvest credentials or sensitive information by luring victims to fake websites. Researchers noted that there was no evidence of further exploitation or installation of backdoors on the compromised routers, indicating a focused campaign aimed specifically at smishing. The campaign's covert nature allowed it to persist for an extended period before detection. Internet scans revealed that over 19,000 Milesight routers have SMS sending APIs, highlighting the scale of potential exposure. Security experts recommend heightened vigilance, advising users to be wary of unsolicited SMS messages, especially those containing suspicious URLs, urgent requests, or grammatical errors. The incident underscores the risks associated with exposed industrial IoT devices and the importance of securing remote management interfaces. Organizations are urged to audit their router configurations, apply available patches, and restrict API access to trusted networks. The use of industrial routers as a platform for mass smishing represents a novel attack vector that could be replicated in other regions or with other device types. The campaign demonstrates the evolving tactics of threat actors in leveraging IoT infrastructure for social engineering attacks. Ongoing monitoring and awareness are essential to mitigate the risks posed by such sophisticated smishing operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On October 1, 2025, public reports disclosed the long-running abuse of Milesight industrial cellular routers for covert SMS phishing campaigns across Europe. Milesight had not responded to media inquiries at the time of publication.
Researchers said that while CVE-2023-43261 is a known vulnerability affecting Milesight routers, not all compromised devices were vulnerable to it, indicating attackers likely used more than one intrusion method. This finding complicated efforts to fully explain and contain the abuse.
Analysis connected the campaign to phishing domains registered through NameSilo and infrastructure associated with Lithuanian hosting provider Podaon. Some phishing sites also used JavaScript evasion and Telegram bots to log victim interactions.
Researchers identified sustained smishing activity targeting users in Belgium, Sweden, Italy, Denmark, and France, with lures spoofing government services, banks, postal organizations, and telecom providers. The SMS messages directed victims to credential-harvesting phishing sites.
Researchers found that unsecured Milesight UR35 industrial cellular routers had been used since at least October 2023 to send large-scale smishing messages. The compromised devices were commonly exposed industrial IoT routers with outdated firmware and accessible APIs.
Threat actors began abusing APIs on compromised Milesight industrial cellular routers to send malicious SMS messages in Europe. Reporting indicates Belgium was targeted from November 2022, including messages impersonating Belgian government platforms such as CSAM and eBox.
3 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcenews.risky.biz
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.