logo

New VOIP-Based Botnet Attacking Routers Configured With Default Password

ID: bfb7b789-2362-5d42-a744-16e935a8808b

STIX ID: report--bfb7b789-2362-5d42-a744-16e935a8808b

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-07-26

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Researchers uncovered a global Telnet-based botnet campaign targeting VOIP-enabled routers and devices with default or weak credentials; analysts observed ~90 malicious IPs from a New Mexico utility and identified ~500 similar infected systems worldwide exhibiting Mirai-like scanning and Telnet brute-force behavior, a shared JA4 network fingerprint, and probable involvement of older Cambium hardware. The report warns that internet-facing, lightly monitored VOIP devices are at high risk, recommends auditing Telnet exposure and rotating or disabling default credentials, and notes attackers monitor public security discussion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.