Huawei A.I CyberSecurity Scoring
Huawei
Company Information
Website:http://www.huawei.com/en/
Employees number:134,994
Number of followers:5,383,705
NAICS:517
Industry Type:Telecommunications
Homepage:huawei.com
Huawei Risk Score (AI oriented)
Between 750 and 799
HuaweiTelecommunications
Updated:
28/07/2026
28/07/2026
796/1000
Fair
Baa
Huawei Global Score (TPRM)
xxxx
HuaweiTelecommunications
Score locked

HuaweiFair
Current Score
796Baa (FAIR)
01000
5 incidents
-12.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
796
JULY 2026
798
Vulnerability
14 Jul 2026 • Huawei
Huawei and TP-Link: Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks
Dysphoria Botnet: A Rapidly Evolving IoT Threat Leveraging Blockchain and Decentralized C2
796
CRITICAL-2
HUATP-1785227245
Dysphoria Botnet: A Rapidly Evolving IoT Threat Leveraging Blockchain and Decentralized C2
A sophisticated IoT botnet named Dysphoria has emerged as a major global cybersecurity threat, employing blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale DDoS operations. First observed by XLAB in Q1 2026, the botnet has undergone aggressive evolution, transitioning from early variants derived from jackskid to more advanced fbot-based implementations within weeks.
### Key Developments and Technical Innovations
- Early Variants (March 2026): Initial samples used Ethereum Name Service (ENS) domains (e.g., m3rnbvs5d.eth) to fetch configuration data, with debug strings like “android has no compatible libc library.”
- April 2026: Newer variants introduced custom RC4-based encryption with Linear Congruential Generator (LCG) shuffling and Linear Feedback Shift Register (LFSR) operations, complicating reverse engineering. Operators expanded ENS usage (e.g., ukranianhorseriding.eth, burrberry.eth) and adopted Solana Name Service (SNS) domains (e.g., 24carnforth2merseyside.sol) for dynamic C2 infrastructure delivery.
- Covert C2 Resolution: Instead of hardcoded servers, infected nodes query ENS/SNS TXT records, extracting obfuscated IP data disguised as fake IPv6 strings. A custom permutation routine reconstructs valid IPv4 addresses, which are used to contact intermediate distribution nodes (e.g., /nodes?key=meowmeowmeow), masking the true C2 servers behind compromised devices.
- Relayization (Late June 2026): A critical shift saw newer variants removing DDoS capabilities entirely, instead functioning as relay/proxy nodes. These exploit UPnP to open up to 155 ports on infected routers, bypassing NAT restrictions via Linux epoll-based asynchronous I/O for high-efficiency bidirectional tunnels.
- Modular Architecture: Dysphoria separates attack execution from infrastructure support, mirroring trends in crimeware-as-a-service (CaaS) ecosystems. Heartbeat reports (e.g., login.trees4sale.net) provide real-time metrics like bandwidth and connection counts, turning infected hosts into distributed assets.
### Propagation and Scale
- Exploited Vulnerabilities: Dysphoria targets a mix of legacy and recent IoT flaws, including:
- CVE-2017-17215 (Huawei HG532e RCE)
- CVE-2020-8515 (DrayTek Vigor RCE)
- CVE-2022-35733 (TP-Link Archer RCE)
- CVE-2025-9528 & CVE-2025-55182 (newer disclosures)
- Primary Infection Vector: Telnet/SSH brute-force attacks remain dominant, targeting routers, cameras, and embedded Linux systems.
- Botnet Size: As of July 2026, Dysphoria has amassed over 200,000 compromised devices, with peak daily C2 sessions reaching 740,000 and 239,000 overseas nodes observed in telemetry (July 14–20, 2026).
- DDoS-for-Hire Services: Leaked backend panels confirm tiered pricing models, with operators advertising up to 4 Tbps attack capacity. Targets include gaming platforms, internet services, and high-availability sectors, with near-daily attack activity.
### Impact and Significance
Dysphoria represents a notable shift in botnet design, integrating:
- Blockchain-based C2 resolution (ENS/SNS) for decentralized infrastructure.
- Relay-based obfuscation to evade takedowns.
- Continuous variant iteration to complicate detection.
Its modular separation of attack and infrastructure, combined with aggressive exploitation of IoT vulnerabilities, underscores the growing convergence of decentralized technologies and cybercrime. Traditional mitigation strategies face challenges due to Dysphoria’s dynamic C2 resolution and resilient proxy network.
Indicators of Compromise (IOCs):
- Hostnames: i.peer4you[.]net, login.trees4sale[.]net, c2.saintpetersburgresident[.]ru, node.androiddebugbridge[.]su (among others).
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
799
MAY 2026
798
APRIL 2026
797
MARCH 2026
797
FEBRUARY 2026
795
JANUARY 2026
795
DECEMBER 2025
796
Vulnerability
01 Dec 2025 • Huawei
Huawei, Tower of Fantasy and Palo Alto Networks: DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity
DragonForce Ransomware Group Abuses Microsoft Teams to Conceal Malicious Traffic in US Firm Breach
792
CRITICAL-4
UNIHUAAME1781792980
DragonForce Ransomware Group Abuses Microsoft Teams to Conceal Malicious Traffic in US Firm Breach
Cybercriminals tied to the DragonForce ransomware group compromised a US-based services firm in late 2025, leveraging a custom backdoor to hide their command-and-control (C2) traffic within Microsoft Teams’ relay infrastructure. Researchers from Broadcom’s Symantec and Carbon Black identified the attack, marking the first known instance of malware abusing Microsoft’s TURN relay to evade detection.
### The Attack: A Multi-Stage Intrusion
The threat actors gained initial access in December 2025, likely through an unpatched SQL/MSSQL vulnerability or via an initial access broker. Once inside, they employed DLL sideloading, abusing a legitimate VirtualBox executable to load malicious code and bypass security tools.
Over one to two months, the attackers:
- Modified firewall rules and system settings to maintain persistence.
- Disabled security defenses using bring-your-own-vulnerable-driver (BYOVD) techniques, exploiting flaws in drivers from Huawei (HWAudioOs2Ec.sys), Topaz Antifraud (CVE-2023-52271), Tower of Fantasy (CVE-2025-61155), and K7 Security Anti-Malware (CVE-2025-1055).
- Deployed Abyss Worker, a malicious driver disguised as a Palo Alto Networks security component.
- Used Havoc Process Terminator to further evade detection.
The final phase involved data exfiltration and DragonForce ransomware deployment, along with the installation of Backdoor.Turn, a Go-based backdoor designed to blend C2 traffic with legitimate Microsoft Teams communications. By routing malicious traffic through Microsoft’s TURN relay servers, the attackers made their activity appear as routine business traffic, bypassing traditional security filters.
### A Shift in Ransomware Tactics
Symantec and Carbon Black researchers described DragonForce’s evolution from a ransomware-as-a-service (RaaS) model to a highly organized cartel, employing custom tooling, advanced evasion techniques, and trusted cloud services to maintain persistence. Cybersecurity experts noted that this approach mirrors state-sponsored threat actor tradecraft, moving beyond opportunistic attacks to long-term, stealthy operations.
The abuse of Microsoft Teams’ infrastructure highlights a growing trend where attackers exploit implicit trust in enterprise collaboration tools, making detection significantly harder. As one expert observed, security systems often whitelist traffic to Microsoft domains, allowing malicious activity to slip through undetected.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
NOVEMBER 2025
796
OCTOBER 2025
826
Breach
06 Oct 2025 • Huawei
Huawei Technologies Co., Ltd.
Alleged Breach of Huawei’s Internal Repositories and Source Code Leak
794
CRITICAL-32
HUA1993019100625
Threat actors have alleged a breach of Huawei’s internal code repositories, claiming to have exfiltrated proprietary source code (including network management software, base station firmware, and security libraries) and development tools. The leaked materials, if verified, expose Huawei’s software architecture, encryption routines, authentication workflows, and potential vulnerabilities, enabling tailored exploits against its global telecommunications infrastructure. The incident heightens geopolitical and national security concerns, particularly for 5G deployments and government networks, as competitors or APT groups could reverse-engineer the code for latent vulnerabilities or sophisticated attacks. While Huawei has not confirmed the breach, the disclosure alone risks eroding trust in its products, potentially leading to delayed approvals, contract revocations, or increased scrutiny from intelligence agencies. Customers are advised to enhance monitoring, patch management, and access controls to mitigate risks from potential zero-day exploits derived from the leak.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
826
MAY 2025
825
Vulnerability
06 May 2025 • Huawei
Langflow
Critical Unauthenticated RCE Vulnerability in Langflow
823
CRITICAL-2
353844050725
A critical unauthenticated remote code execution vulnerability in Langflow was added to CISA’s Known Exploited Vulnerabilities catalog after proof of active exploitation emerged. Langflow, an open-source Python tool used by organizations to visually build and deploy AI agents via a web interface and API, inadvertently exposed more than 500 internet-facing instances and countless internal deployments to hostile actors. By abusing CVE-2025-3248, attackers can execute arbitrary code on exposed servers without any authentication, potentially leading to full system compromise, data theft, ransomware deployment, or pivoting to deeper network resources. Given Langflow’s popularity in automating sensitive workflows, the flaw poses an immediate threat to intellectual property, customer records, and operational continuity across both public and private sector environments. If left unpatched, adversaries could manipulate or leak proprietary AI models, harvest credentials, disrupt services, and undermine trust in critical automation pipelines. CISA’s inclusion of this vulnerability in its KEV catalog underscores the urgent need for patching to prevent widespread damage to organizational integrity and the broader digital infrastructure reliant on Langflow.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2024
832
Cyber Attack
01 Nov 2024 • Huawei
NETGEAR, Huawei, TP-Link and D-Link: Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices
Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach
824
LOW-8
HUADLITP-NET1775672907
Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach
Cybersecurity researchers have uncovered Masjesu, a sophisticated botnet operating as a DDoS-for-hire service since 2023. Marketed via Telegram under the alias XorBot, the malware targets IoT devices including routers, cameras, and gateways across multiple architectures, employing XOR-based encryption to evade detection.
First documented by Chinese security firm NSFOCUS in December 2023 and linked to an operator known as synmaestro, Masjesu has since evolved. A 2024 update introduced 12 new exploits targeting devices from D-Link, Huawei, NETGEAR, TP-Link, and others, alongside enhanced DDoS flood modules. Researchers note its rapid growth, with attackers increasingly leveraging Telegram for recruitment and promotion.
Trellix’s recent analysis reveals Masjesu’s focus on volumetric DDoS attacks, particularly against CDNs, game servers, and enterprises. The botnet’s infrastructure is heavily concentrated in Vietnam (nearly 50% of observed traffic), with additional activity in Ukraine, Iran, Brazil, Kenya, and India. Once deployed, the malware establishes persistence, disables competing processes, and connects to command servers to execute attacks.
Masjesu also self-propagates by scanning for vulnerable devices, including Realtek routers via port 52869 a tactic previously used by botnets like JenX and Satori. Notably, the botnet avoids high-profile targets like the U.S. Department of Defense to minimize legal scrutiny, prioritizing long-term survival over mass infection.
As IoT exploitation expands, Masjesu’s low-visibility approach and social media-driven recruitment underscore its adaptability as a persistent cyber threat.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Huawei ??
What was Huawei's A.I Rankiteo Cyber Score in July 2026 ??
What was Huawei's A.I Rankiteo Cyber Score in June 2026 ??
What was Huawei's A.I Rankiteo Cyber Score in May 2026 ??
What was Huawei's A.I Rankiteo Cyber Score in April 2026 ??
What was Huawei's A.I Rankiteo Cyber Score in March 2026 ??
What was Huawei's A.I Rankiteo Cyber Score in February 2026 ??
What was Huawei's A.I Rankiteo Cyber Score in January 2026 ??
What was Huawei's A.I Rankiteo Cyber Score in December 2025 ??
What was Huawei's A.I Rankiteo Cyber Score in November 2025 ??
What was Huawei's A.I Rankiteo Cyber Score in October 2025 ??
What was Huawei's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Huawei's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Huawei ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Huawei's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?