logo

Zimperium Discovers Full-Duplex ICMP Redirect Attacks in the Wild

ID: 4fbf91e2-7c79-5e31-a644-44cd69afd9e2

STIX ID: report--4fbf91e2-7c79-5e31-a644-44cd69afd9e2

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2014-11-20

Date Updated: 2026-05-01

...
...

Zimperium researchers describe "DoubleDirect", a full‑duplex ICMP Redirect MITM technique observed in the wild that redirects mobile device traffic (DNS and downstream IPs) through an attacker-controlled host to steal credentials and deliver malware. The report includes a proof‑of‑concept tool, configuration and execution details, lists affected platforms (iOS, many Android devices, macOS), observed incidents across multiple countries, and recommended mitigations such as disabling ICMP redirects and vendor fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.