Risky Bulletin Newsletter
October 01, 2025
Risky Bulletin: Router APIs abused to send SMS spam waves
Presented by
News Editor
A mysterious threat actor is abusing Milesight industrial cellular routers to send SMS spam, also known as smishing, to users in several European countries.
According to French security firm Sekoia, the campaign has been silently going on without detection since at least February 2022.
The attackers are targeting a feature of Milesight routers that lets admins configure to receive SMS alerts. Such a feature is common in industrial routers that connect remote equipment to a larger network via a cellular modem, with admins receiving alerts when the equipment connection goes offline and may not be in a state where it can be managed.