Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Global SMS Phishing Campaign Traced to China Targets Users Worldwide

A sophisticated smishing campaign originating from China has been identified as a significant threat to global users.

A sophisticated smishing campaign originating from China has been identified as a significant threat to global users.

The campaign, attributed to the group known as the Smishing Triad, demonstrates remarkable scale and complexity. Utilizing a decentralized infrastructure, the group is capable of registering thousands of malicious domains daily.

Since January 2024, over 194,000 malicious domains have been identified. The campaign has been targeting U.S. residents since April 2024 and is rapidly expanding its global reach.

The attack leverages fraudulent toll violation and package misdelivery notices sent via SMS to create urgency and manipulate recipients into action. Over recent months, the campaign has evolved from a phishing kit marketplace into an active community within the Phishing-as-a-Service (PhaaS) ecosystem.

Attackers impersonate legitimate services across sectors such as banking, cryptocurrency, e-commerce, healthcare, law enforcement, and social media. The social engineering tactics have advanced, using personalized information and realistic phishing pages to extract sensitive data, including National Identification Numbers, addresses, payment details, and login credentials.

A sophisticated smishing campaign originating from China has been identified as a significant threat to global users.
Leo Underwood · Thehackingpost

Global Scale and Infrastructure Sophistication

The campaign's infrastructure is highly organized, with domains registered through a Hong Kong-based registrar and hosted primarily on U.S. cloud services, particularly within the Cloudflare network. Domain registration analysis shows a shift in WHOIS creation dates, with a focus on mimicking legitimate services through hyphenated naming structures.

For instance, domains such as "irs.gov-addpayment[.]info" are designed to resemble official websites. The U.S. Postal Service is the most commonly impersonated service, with nearly 28,000 phishing domains, while toll services account for approximately 90,000 domains.

Most domains have short lifespans, with approximately 29% active for two days or less and over 82% expiring within two weeks.

The operation functions within a sophisticated PhaaS ecosystem, with specialized actors managing different stages of the attack supply chain. Upstream participants include data brokers and domain sellers, while downstream operations involve SMS and RCS delivery, supported by specialists verifying phone numbers and monitoring blocklists.

Advertisement

The campaign continues to evolve, with a recent shift towards "gov-" domain registrations to better impersonate government services. Messages typically originate from Philippine country codes, though U.S. numbers are increasingly used.

Security experts advise caution with unsolicited messages from unknown senders, recommending verification through official websites or applications and avoiding links or numbers in suspicious messages.

This campaign illustrates the significant threat posed by organized phishing operations with global reach and sophisticated infrastructure.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories