New VOIP-Based Botnet Attacking Routers Configured With Default Password
ID: bfb7b789-2362-5d42-a744-16e935a8808b
STIX ID: report--bfb7b789-2362-5d42-a744-16e935a8808b
Feed Name: cybersecurityNews.com
Researchers uncovered a global Telnet-based botnet campaign targeting VOIP-enabled routers and devices with default or weak credentials; analysts observed ~90 malicious IPs from a New Mexico utility and identified ~500 similar infected systems worldwide exhibiting Mirai-like scanning and Telnet brute-force behavior, a shared JA4 network fingerprint, and probable involvement of older Cambium hardware. The report warns that internet-facing, lightly monitored VOIP devices are at high risk, recommends auditing Telnet exposure and rotating or disabling default credentials, and notes attackers monitor public security discussion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
