Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Huawei

Huawei Vendor Cyber Rating & Cyber Score

huawei.com

Huawei is a leading global provider of information and communications technology (ICT) infrastructure and smart devices. With integrated solutions across four key domains – telecom networks, IT, smart devices, and cloud services – we are committed to bringing digital to every person, home and organization for a fully connected, intelligent world. Huawei's end-to-end portfolio of products, solutions and services are both competitive and secure. Through open collaboration with ecosystem partners, we create lasting value for our customers, working to empower people, enrich home life, and inspire innovation in organizations of all shapes and sizes. At Huawei, innovation focuses on customer needs. We invest heavily in basic research,


Huawei A.I CyberSecurity Scoring

Huawei
Company Information
Website:http://www.huawei.com/en/
Employees number:134,994
Number of followers:5,383,705
NAICS:517
Industry Type:Telecommunications
Homepage:huawei.com
Huawei Risk Score (AI oriented)
Between 750 and 799
logo
HuaweiTelecommunications
Updated:
28/07/2026
796/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Huawei Global Score (TPRM)
xxxx
logo
HuaweiTelecommunications
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Huawei
HuaweiFair
Current Score
796Baa (FAIR)
01000
5 incidents
-12.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
796Before Incident
JULY 2026
798Before Incident
Vulnerability
14 Jul 2026Huawei
Huawei and TP-Link: Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks

Dysphoria Botnet: A Rapidly Evolving IoT Threat Leveraging Blockchain and Decentralized C2

796After Incident
CRITICAL-2
HUATP-1785227245
Dysphoria Botnet: A Rapidly Evolving IoT Threat Leveraging Blockchain and Decentralized C2 A sophisticated IoT botnet named Dysphoria has emerged as a major global cybersecurity threat, employing blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale DDoS operations. First observed by XLAB in Q1 2026, the botnet has undergone aggressive evolution, transitioning from early variants derived from jackskid to more advanced fbot-based implementations within weeks. ### Key Developments and Technical Innovations - Early Variants (March 2026): Initial samples used Ethereum Name Service (ENS) domains (e.g., m3rnbvs5d.eth) to fetch configuration data, with debug strings like “android has no compatible libc library.” - April 2026: Newer variants introduced custom RC4-based encryption with Linear Congruential Generator (LCG) shuffling and Linear Feedback Shift Register (LFSR) operations, complicating reverse engineering. Operators expanded ENS usage (e.g., ukranianhorseriding.eth, burrberry.eth) and adopted Solana Name Service (SNS) domains (e.g., 24carnforth2merseyside.sol) for dynamic C2 infrastructure delivery. - Covert C2 Resolution: Instead of hardcoded servers, infected nodes query ENS/SNS TXT records, extracting obfuscated IP data disguised as fake IPv6 strings. A custom permutation routine reconstructs valid IPv4 addresses, which are used to contact intermediate distribution nodes (e.g., /nodes?key=meowmeowmeow), masking the true C2 servers behind compromised devices. - Relayization (Late June 2026): A critical shift saw newer variants removing DDoS capabilities entirely, instead functioning as relay/proxy nodes. These exploit UPnP to open up to 155 ports on infected routers, bypassing NAT restrictions via Linux epoll-based asynchronous I/O for high-efficiency bidirectional tunnels. - Modular Architecture: Dysphoria separates attack execution from infrastructure support, mirroring trends in crimeware-as-a-service (CaaS) ecosystems. Heartbeat reports (e.g., login.trees4sale.net) provide real-time metrics like bandwidth and connection counts, turning infected hosts into distributed assets. ### Propagation and Scale - Exploited Vulnerabilities: Dysphoria targets a mix of legacy and recent IoT flaws, including: - CVE-2017-17215 (Huawei HG532e RCE) - CVE-2020-8515 (DrayTek Vigor RCE) - CVE-2022-35733 (TP-Link Archer RCE) - CVE-2025-9528 & CVE-2025-55182 (newer disclosures) - Primary Infection Vector: Telnet/SSH brute-force attacks remain dominant, targeting routers, cameras, and embedded Linux systems. - Botnet Size: As of July 2026, Dysphoria has amassed over 200,000 compromised devices, with peak daily C2 sessions reaching 740,000 and 239,000 overseas nodes observed in telemetry (July 14–20, 2026). - DDoS-for-Hire Services: Leaked backend panels confirm tiered pricing models, with operators advertising up to 4 Tbps attack capacity. Targets include gaming platforms, internet services, and high-availability sectors, with near-daily attack activity. ### Impact and Significance Dysphoria represents a notable shift in botnet design, integrating: - Blockchain-based C2 resolution (ENS/SNS) for decentralized infrastructure. - Relay-based obfuscation to evade takedowns. - Continuous variant iteration to complicate detection. Its modular separation of attack and infrastructure, combined with aggressive exploitation of IoT vulnerabilities, underscores the growing convergence of decentralized technologies and cybercrime. Traditional mitigation strategies face challenges due to Dysphoria’s dynamic C2 resolution and resilient proxy network. Indicators of Compromise (IOCs): - Hostnames: i.peer4you[.]net, login.trees4sale[.]net, c2.saintpetersburgresident[.]ru, node.androiddebugbridge[.]su (among others).
INCIDENT DETAILS -
TYPE
Botnet, DDoS, IoT Exploitation
MOTIVATION
Financial gain (DDoS-for-hire)Cybercrime-as-a-Service (CaaS)
IMPACT
Systems Affected: Over 200,000 IoT devices (routers, cameras, embedded Linux systems)Operational Impact: Large-scale DDoS attacks targeting gaming platforms, internet services, and high-availability sectors
DATA BREACH
Data Encryption: Custom RC4-based encryption with LCG shuffling and LFSR operations
JUNE 2026
799Before Incident
MAY 2026
798Before Incident
APRIL 2026
797Before Incident
MARCH 2026
797Before Incident
FEBRUARY 2026
795Before Incident
JANUARY 2026
795Before Incident
DECEMBER 2025
796Before Incident
Vulnerability
01 Dec 2025Huawei
Huawei, Tower of Fantasy and Palo Alto Networks: DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity

DragonForce Ransomware Group Abuses Microsoft Teams to Conceal Malicious Traffic in US Firm Breach

792After Incident
CRITICAL-4
UNIHUAAME1781792980
DragonForce Ransomware Group Abuses Microsoft Teams to Conceal Malicious Traffic in US Firm Breach Cybercriminals tied to the DragonForce ransomware group compromised a US-based services firm in late 2025, leveraging a custom backdoor to hide their command-and-control (C2) traffic within Microsoft Teams’ relay infrastructure. Researchers from Broadcom’s Symantec and Carbon Black identified the attack, marking the first known instance of malware abusing Microsoft’s TURN relay to evade detection. ### The Attack: A Multi-Stage Intrusion The threat actors gained initial access in December 2025, likely through an unpatched SQL/MSSQL vulnerability or via an initial access broker. Once inside, they employed DLL sideloading, abusing a legitimate VirtualBox executable to load malicious code and bypass security tools. Over one to two months, the attackers: - Modified firewall rules and system settings to maintain persistence. - Disabled security defenses using bring-your-own-vulnerable-driver (BYOVD) techniques, exploiting flaws in drivers from Huawei (HWAudioOs2Ec.sys), Topaz Antifraud (CVE-2023-52271), Tower of Fantasy (CVE-2025-61155), and K7 Security Anti-Malware (CVE-2025-1055). - Deployed Abyss Worker, a malicious driver disguised as a Palo Alto Networks security component. - Used Havoc Process Terminator to further evade detection. The final phase involved data exfiltration and DragonForce ransomware deployment, along with the installation of Backdoor.Turn, a Go-based backdoor designed to blend C2 traffic with legitimate Microsoft Teams communications. By routing malicious traffic through Microsoft’s TURN relay servers, the attackers made their activity appear as routine business traffic, bypassing traditional security filters. ### A Shift in Ransomware Tactics Symantec and Carbon Black researchers described DragonForce’s evolution from a ransomware-as-a-service (RaaS) model to a highly organized cartel, employing custom tooling, advanced evasion techniques, and trusted cloud services to maintain persistence. Cybersecurity experts noted that this approach mirrors state-sponsored threat actor tradecraft, moving beyond opportunistic attacks to long-term, stealthy operations. The abuse of Microsoft Teams’ infrastructure highlights a growing trend where attackers exploit implicit trust in enterprise collaboration tools, making detection significantly harder. As one expert observed, security systems often whitelist traffic to Microsoft domains, allowing malicious activity to slip through undetected.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
NOVEMBER 2025
796Before Incident
OCTOBER 2025
826Before Incident
Breach
06 Oct 2025Huawei
Huawei Technologies Co., Ltd.

Alleged Breach of Huawei’s Internal Repositories and Source Code Leak

794After Incident
CRITICAL-32
HUA1993019100625
Threat actors have alleged a breach of Huawei’s internal code repositories, claiming to have exfiltrated proprietary source code (including network management software, base station firmware, and security libraries) and development tools. The leaked materials, if verified, expose Huawei’s software architecture, encryption routines, authentication workflows, and potential vulnerabilities, enabling tailored exploits against its global telecommunications infrastructure. The incident heightens geopolitical and national security concerns, particularly for 5G deployments and government networks, as competitors or APT groups could reverse-engineer the code for latent vulnerabilities or sophisticated attacks. While Huawei has not confirmed the breach, the disclosure alone risks eroding trust in its products, potentially leading to delayed approvals, contract revocations, or increased scrutiny from intelligence agencies. Customers are advised to enhance monitoring, patch management, and access controls to mitigate risks from potential zero-day exploits derived from the leak.
INCIDENT DETAILS -
TYPE
Data BreachSource Code LeakUnauthorized Access
MOTIVATION
Financial Gain (sale of source code)Reputation (underground forum credibility)Potential Espionage or Competitive Advantage
IMPACT
Proprietary source codeDevelopment toolsTechnical documentationNetwork management softwareBase station firmwareSecurity librariesHuawei internal repositoriesCode development environmentsPotential downstream telecommunications equipmentPotential erosion of trust in Huawei productsReassessment of risk posture by intelligence agencies and corporate security teamsPossible delays or revocations of Huawei product approvalsHigh (geopolitical and national security concerns amplified)Potential loss of customer confidenceCompetitors may exploit leaked code for reverse-engineering
DATA BREACH
Proprietary source codeTechnical documentationDevelopment toolsSecurity librariesSensitivity Of Data: High (includes encryption routines, authentication workflows, potential vulnerabilities)Data Exfiltration: Alleged (unverified)Source code filesFirmwareDocumentation
SEPTEMBER 2025
826Before Incident
MAY 2025
825Before Incident
Vulnerability
06 May 2025Huawei
Langflow

Critical Unauthenticated RCE Vulnerability in Langflow

823After Incident
CRITICAL-2
353844050725
A critical unauthenticated remote code execution vulnerability in Langflow was added to CISA’s Known Exploited Vulnerabilities catalog after proof of active exploitation emerged. Langflow, an open-source Python tool used by organizations to visually build and deploy AI agents via a web interface and API, inadvertently exposed more than 500 internet-facing instances and countless internal deployments to hostile actors. By abusing CVE-2025-3248, attackers can execute arbitrary code on exposed servers without any authentication, potentially leading to full system compromise, data theft, ransomware deployment, or pivoting to deeper network resources. Given Langflow’s popularity in automating sensitive workflows, the flaw poses an immediate threat to intellectual property, customer records, and operational continuity across both public and private sector environments. If left unpatched, adversaries could manipulate or leak proprietary AI models, harvest credentials, disrupt services, and undermine trust in critical automation pipelines. CISA’s inclusion of this vulnerability in its KEV catalog underscores the urgent need for patching to prevent widespread damage to organizational integrity and the broader digital infrastructure reliant on Langflow.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
Data TheftSystem CompromiseRansomware DeploymentPivoting to Deeper Network Resources
IMPACT
Intellectual PropertyCustomer RecordsSystems Affected: Langflow deploymentsOperational Impact: Operational ContinuityBrand Reputation Impact: Undermine Trust in Critical Automation Pipelines
DATA BREACH
Intellectual PropertyCustomer RecordsSensitivity Of Data: High
NOVEMBER 2024
832Before Incident
Cyber Attack
01 Nov 2024Huawei
NETGEAR, Huawei, TP-Link and D-Link: Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach

824After Incident
LOW-8
HUADLITP-NET1775672907
Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach Cybersecurity researchers have uncovered Masjesu, a sophisticated botnet operating as a DDoS-for-hire service since 2023. Marketed via Telegram under the alias XorBot, the malware targets IoT devices including routers, cameras, and gateways across multiple architectures, employing XOR-based encryption to evade detection. First documented by Chinese security firm NSFOCUS in December 2023 and linked to an operator known as synmaestro, Masjesu has since evolved. A 2024 update introduced 12 new exploits targeting devices from D-Link, Huawei, NETGEAR, TP-Link, and others, alongside enhanced DDoS flood modules. Researchers note its rapid growth, with attackers increasingly leveraging Telegram for recruitment and promotion. Trellix’s recent analysis reveals Masjesu’s focus on volumetric DDoS attacks, particularly against CDNs, game servers, and enterprises. The botnet’s infrastructure is heavily concentrated in Vietnam (nearly 50% of observed traffic), with additional activity in Ukraine, Iran, Brazil, Kenya, and India. Once deployed, the malware establishes persistence, disables competing processes, and connects to command servers to execute attacks. Masjesu also self-propagates by scanning for vulnerable devices, including Realtek routers via port 52869 a tactic previously used by botnets like JenX and Satori. Notably, the botnet avoids high-profile targets like the U.S. Department of Defense to minimize legal scrutiny, prioritizing long-term survival over mass infection. As IoT exploitation expands, Masjesu’s low-visibility approach and social media-driven recruitment underscore its adaptability as a persistent cyber threat.
INCIDENT DETAILS -
TYPE
DDoS-for-Hire Botnet
MOTIVATION
Financial gain (DDoS-for-hire service)Long-term survival with low visibility
IMPACT
IoT devices (routers, cameras, gateways)Disruption of CDNs, game servers, and enterprises via volumetric DDoS attacks
DATA BREACH
Data Encryption: XOR-based encryption

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Huawei ?
?
What was Huawei's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Huawei's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Huawei's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Huawei's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Huawei's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Huawei's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Huawei ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Huawei's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Huawei Cyber Scoring History | Rankiteo