Threat Actors Imitate Popular Brands in New Malware Distribution Campaigns
Recent cybersecurity analyses have identified a sophisticated resurgence of smishing campaigns. Cybercriminals are embedding well-known brand names into deceptive URLs and group messaging threads to deceive users into downloading malware.
Recent cybersecurity analyses have identified a sophisticated resurgence of smishing campaigns. Cybercriminals are embedding well-known brand names into deceptive URLs and group messaging threads to deceive users into downloading malware.
Attackers are inserting familiar company names before the “@” symbol in links, exploiting users’ trust in established entities such as FedEx and Microsoft. This technique, combined with deceptively aged hostnames and orchestrated group texts, has led to a marked increase in successful infections.
URLs crafted by attackers appear legitimate by placing a well-known brand name immediately before an “@” symbol, followed by a non-affiliated domain. The true domain, often similar to “soogb[.]xin”, hosts malicious payloads. Victims clicking these links are redirected to download trojanized apps or installers that covertly install backdoors and credential harvesters.
Several recent group text scams have exploited this technique by sending simultaneous messages to multiple recipients, often under the guise of a widespread shipping delay or urgent service update. Recipients see their own and others’ phone numbers listed in the group thread, creating a false sense of legitimacy. One such scam involved a thread posing as “FedEx® Ground Reschedule Your Shipment Delivery,” which prompted users to click a tracking link that instead initiated the download of a remote access trojan.
Recent cybersecurity analyses have identified a sophisticated resurgence of smishing campaigns.
Threat actors have been registering domain names months in advance to circumvent reputation-based defenses. These aged hostnames, sometimes registered six to eight months prior to their first use, appear more credible to spam filters and endpoint protection platforms. By staging their infrastructure, operators ensure that by the time they launch the campaign, the domains are mature enough to avoid automated takedown or flagging.
In several instances, attackers have utilized RCS (Rich Communication Services) protocol features to enhance message presentation on Android devices, displaying company logos and sanitized user interfaces that mimic official apps. SMS sender IDs are spoofed to reflect genuine corporate numbers, further reducing suspicion among recipients.
Upon following the deceptive URL, users are prompted to download an Android APK or Windows installer masquerading as a shipping confirmation app or customer support utility. These installers deploy keyloggers and remote access tools such as Orcus RAT and Cerberus Android malware, capable of exfiltrating SMS messages, authentication tokens, and contact lists. Some payloads also include modules for intercepting two-factor authentication codes and propagating through victims’ contact lists via automatic group message invitations.
Adopt mobile security solutions that perform deep URL analysis, including detection of “@”-style obfuscation in links. Implement network filtering rules to block access to newly created or infrequently used domains. Educate users about the subtle indicators of malicious URLs, emphasizing that legitimate messages will never redirect through non-brand domains.
Security teams are advised to monitor for indicators of compromise related to these cleverly formatted links and group message patterns. Blocking suspicious hostnames at the DNS level and reinforcing SMS gateway filtering with threat intelligence feeds can significantly reduce exposure. Collaboration with mobile carriers to authenticate sender IDs and rapid takedown of malicious infrastructure will be critical to mitigating these deceptive smishing attacks.
Based on reporting by GBHackers.
