Global SMS Phishing Campaign Traced to China Targets Users Worldwide
A sophisticated smishing campaign originating from China has been identified as a significant threat to global users.
A sophisticated smishing campaign originating from China has been identified as a significant threat to global users.
The campaign, attributed to the group known as the Smishing Triad, demonstrates remarkable scale and complexity. Utilizing a decentralized infrastructure, the group is capable of registering thousands of malicious domains daily.
Since January 2024, over 194,000 malicious domains have been identified. The campaign has been targeting U.S. residents since April 2024 and is rapidly expanding its global reach.
The attack leverages fraudulent toll violation and package misdelivery notices sent via SMS to create urgency and manipulate recipients into action. Over recent months, the campaign has evolved from a phishing kit marketplace into an active community within the Phishing-as-a-Service (PhaaS) ecosystem.
Attackers impersonate legitimate services across sectors such as banking, cryptocurrency, e-commerce, healthcare, law enforcement, and social media. The social engineering tactics have advanced, using personalized information and realistic phishing pages to extract sensitive data, including National Identification Numbers, addresses, payment details, and login credentials.
A sophisticated smishing campaign originating from China has been identified as a significant threat to global users.
Global Scale and Infrastructure Sophistication
The campaign's infrastructure is highly organized, with domains registered through a Hong Kong-based registrar and hosted primarily on U.S. cloud services, particularly within the Cloudflare network. Domain registration analysis shows a shift in WHOIS creation dates, with a focus on mimicking legitimate services through hyphenated naming structures.
For instance, domains such as "irs.gov-addpayment[.]info" are designed to resemble official websites. The U.S. Postal Service is the most commonly impersonated service, with nearly 28,000 phishing domains, while toll services account for approximately 90,000 domains.
Most domains have short lifespans, with approximately 29% active for two days or less and over 82% expiring within two weeks.
The operation functions within a sophisticated PhaaS ecosystem, with specialized actors managing different stages of the attack supply chain. Upstream participants include data brokers and domain sellers, while downstream operations involve SMS and RCS delivery, supported by specialists verifying phone numbers and monitoring blocklists.
The campaign continues to evolve, with a recent shift towards "gov-" domain registrations to better impersonate government services. Messages typically originate from Philippine country codes, though U.S. numbers are increasingly used.
Security experts advise caution with unsolicited messages from unknown senders, recommending verification through official websites or applications and avoiding links or numbers in suspicious messages.
This campaign illustrates the significant threat posed by organized phishing operations with global reach and sophisticated infrastructure.
Based on reporting by GBHackers.
