ViciousTrap - Infiltrate, Control, Lure: Turning edge devices into honeypots en masse.

May 23, 2025, 7:09 p.m.

Description

A threat actor nicknamed ViciousTrap has compromised over 5,500 edge devices, transforming them into honeypots. The actor targets more than 50 brands of SOHO routers, SSL VPNs, DVRs, and BMC controllers, possibly to collect exploited vulnerabilities. The infection chain involves exploiting CVE-2023-20118 to deploy a script called NetGhost, which redirects incoming traffic to the attacker's infrastructure. The compromised devices, mostly end-of-life, are used to create a distributed honeypot-like network across Asia. The actor, likely of Chinese-speaking origin, may be attempting to observe exploitation attempts and collect non-public or zero-day exploits. The infrastructure uses servers in Malaysia, and the campaign has been ongoing since March 2025.

Date

  • Created: May 23, 2025, 6:38 p.m.
  • Published: May 23, 2025, 6:38 p.m.
  • Modified: May 23, 2025, 7:09 p.m.

Indicators

  • d92d2f102e1e417894bd2920e477638edfae7f08d78aee605b1ba799507e3e77
  • 20dff1120d968330c703aa485b3ea0ece45a227563ca0ffa395e4e59474dc6bd
  • 212.232.23.217
  • 212.232.23.168
  • 212.232.23.143
  • 155.254.60.160
  • 111.90.148.151
  • 101.99.94.173
  • 101.99.91.239
  • 101.99.91.151
  • 101.99.90.20
  • 111.90.148.112
  • 103.56.17.163
  • 103.43.19.61
  • 103.43.18.59

Attack Patterns

Linked vulnerabilities