Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages

0
Medium
Published: 06/03/2026 (06/03/2026, 13:18:23 UTC)
Source: AlienVault OTX General

Description

A sophisticated smishing and phishing operation active since the second half of 2025 has impersonated over 267 brands across 72 countries, with particular concentration in Latin America. The campaign generated 4,389 phishing domain instances, with Mexico accounting for 1,851 cases. Telecommunications is the most targeted sector with 1,754 instances, followed by financial services and consumer rewards programs. The operation employs fake Cloudflare error pages as decoys, revealing malicious content only to victims matching specific geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. Approximately 30% of infrastructure is hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain progresses from SMS lures through progressive credential harvesting, ultimately capturing complete credit card details including CVV codes.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/04/2026, 09:18:29 UTC

Technical Analysis

This is a sophisticated smishing and phishing operation active since the second half of 2025 that impersonates over 267 brands across 72 countries, with a concentration in Latin America. It generated 4,389 phishing domains, with Mexico heavily targeted. The campaign primarily targets telecommunications, financial services, and consumer rewards sectors. It uses fake Cloudflare error 524 pages as decoys, revealing malicious content selectively based on geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. The infrastructure is partially hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain involves SMS lures leading to progressive credential harvesting and theft of complete credit card details including CVV codes.

Potential Impact

The campaign results in credential theft and financial fraud through the capture of complete credit card details, including CVV codes. It affects multiple sectors, predominantly telecommunications and financial services, across at least 72 countries with a strong focus on Latin America. The use of decoy error pages and selective targeting increases the likelihood of successful victim engagement and evasion of detection.

Mitigation Recommendations

As this is a social engineering campaign rather than a software vulnerability, no patch or official fix exists. Organizations should focus on user awareness training about smishing and phishing risks, especially regarding SMS messages impersonating trusted brands. Monitoring for and blocking known phishing domains and IP indicators associated with this campaign can help reduce exposure. The vendor advisory does not indicate any automated mitigation or patch. Defensive measures should be tailored to detect and respond to phishing attempts and credential harvesting activities.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/error-524-decoy-smishing/"]
Adversary
null
Pulse Id
6a20299f34e4961fdaff1615
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip154.81.166.17
ip43.159.168.186
CC=US ASN=AS132203 tencent building kejizhongyi avenue
ip43.162.84.202
CC=IN ASN=ASNone
ip43.165.6.36
CC=SG ASN=ASNone
ip45.135.162.90
CC=US ASN=AS46562 performive llc
ip47.82.154.2
CC=US ASN=ASNone
ip8.222.134.149
CC=SG ASN=ASNone

Threat ID: 6a213f67e29bf47b5086e260

Added to database: 06/04/2026, 09:03:35 UTC

Last enriched: 06/04/2026, 09:18:29 UTC

Last updated: 07/30/2026, 20:16:25 UTC

Views: 211

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses