logo

ViciousTrap – Infiltrate, Control, Lure: Turning edge devices into honeypots en masse. 

ID: 2a0ccdd3-0e72-53c6-8424-7a9357bff97d

STIX ID: report--2a0ccdd3-0e72-53c6-8424-7a9357bff97d

Feed Name: Sekoia.io Blog

Threat Score
72/100

Date Published: 2025-05-22

Date Updated: 2026-04-29

Author: Felix Aimé, Jeremy Scion and Sekoia TDR

...
...

Sekoia.io TDR discovered and analysed an active campaign by a threat actor named ViciousTrap that exploited CVE-2023-20118 and other flaws to compromise over 5,000 edge devices (routers, DVRs, BMCs, etc.), deploy a MIPS wget and a redirection script called NetGhost to forward inbound traffic to attacker-controlled interception servers, enabling large-scale passive monitoring/Man-in-the-Middle of traffic and reuse of captured webshells; the report provides the infection chain, monitored device types, infrastructure IPs and certificates, detection methods, and IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.