ViciousTrap – Infiltrate, Control, Lure: Turning edge devices into honeypots en masse.
ID: 2a0ccdd3-0e72-53c6-8424-7a9357bff97d
STIX ID: report--2a0ccdd3-0e72-53c6-8424-7a9357bff97d
Feed Name: Sekoia.io Blog
Date Published: 2025-05-22
Date Updated: 2026-04-29
Author: Felix Aimé, Jeremy Scion and Sekoia TDR
Sekoia.io TDR discovered and analysed an active campaign by a threat actor named ViciousTrap that exploited CVE-2023-20118 and other flaws to compromise over 5,000 edge devices (routers, DVRs, BMCs, etc.), deploy a MIPS wget and a redirection script called NetGhost to forward inbound traffic to attacker-controlled interception servers, enabling large-scale passive monitoring/Man-in-the-Middle of traffic and reuse of captured webshells; the report provides the infection chain, monitored device types, infrastructure IPs and certificates, detection methods, and IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
