ViciousTrap: Turning Edge Devices into Honeypots at Scale
ID: 087377a1-43b0-5249-ace3-5a056892fadf
STIX ID: report--087377a1-43b0-5249-ace3-5a056892fadf
Feed Name: Sekoia.com
Sekoia.io observed a sustained campaign (ViciousTrap) exploiting CVE-2023-20118 and other EOL device vulnerabilities to install a NetGhost redirection script that forwards inbound traffic from compromised routers and appliances to attacker-controlled servers, enabling large-scale Man-in-the-Middle observation. The actor has compromised thousands of devices across many countries, reuses a privately held webshell, maintains exploitation/notification/interception infrastructure (notably hosted in AS45839), and publishes numerous IoCs including IPs, binaries, and certificate fingerprints to aid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
