Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages
A sophisticated smishing and phishing operation active since the second half of 2025 has impersonated over 267 brands across 72 countries, with particular concentration in Latin America. The campaign generated 4,389 phishing domain instances, with Mexico accounting for 1,851 cases. Telecommunications is the most targeted sector with 1,754 instances, followed by financial services and consumer rewards programs. The operation employs fake Cloudflare error pages as decoys, revealing malicious content only to victims matching specific geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. Approximately 30% of infrastructure is hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain progresses from SMS lures through progressive credential harvesting, ultimately capturing complete credit card details including CVV codes.
AI Analysis
Technical Summary
This is a sophisticated smishing and phishing operation active since the second half of 2025 that impersonates over 267 brands across 72 countries, with a concentration in Latin America. It generated 4,389 phishing domains, with Mexico heavily targeted. The campaign primarily targets telecommunications, financial services, and consumer rewards sectors. It uses fake Cloudflare error 524 pages as decoys, revealing malicious content selectively based on geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. The infrastructure is partially hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain involves SMS lures leading to progressive credential harvesting and theft of complete credit card details including CVV codes.
Potential Impact
The campaign results in credential theft and financial fraud through the capture of complete credit card details, including CVV codes. It affects multiple sectors, predominantly telecommunications and financial services, across at least 72 countries with a strong focus on Latin America. The use of decoy error pages and selective targeting increases the likelihood of successful victim engagement and evasion of detection.
Mitigation Recommendations
As this is a social engineering campaign rather than a software vulnerability, no patch or official fix exists. Organizations should focus on user awareness training about smishing and phishing risks, especially regarding SMS messages impersonating trusted brands. Monitoring for and blocking known phishing domains and IP indicators associated with this campaign can help reduce exposure. The vendor advisory does not indicate any automated mitigation or patch. Defensive measures should be tailored to detect and respond to phishing attempts and credential harvesting activities.
Affected Countries
Australia, Chile, Colombia, Germany, Mexico, Netherlands
Indicators of Compromise
- ip: 154.81.166.17
- ip: 43.159.168.186
- ip: 43.162.84.202
- ip: 43.165.6.36
- ip: 45.135.162.90
- ip: 47.82.154.2
- ip: 8.222.134.149
Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages
Description
A sophisticated smishing and phishing operation active since the second half of 2025 has impersonated over 267 brands across 72 countries, with particular concentration in Latin America. The campaign generated 4,389 phishing domain instances, with Mexico accounting for 1,851 cases. Telecommunications is the most targeted sector with 1,754 instances, followed by financial services and consumer rewards programs. The operation employs fake Cloudflare error pages as decoys, revealing malicious content only to victims matching specific geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. Approximately 30% of infrastructure is hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain progresses from SMS lures through progressive credential harvesting, ultimately capturing complete credit card details including CVV codes.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This is a sophisticated smishing and phishing operation active since the second half of 2025 that impersonates over 267 brands across 72 countries, with a concentration in Latin America. It generated 4,389 phishing domains, with Mexico heavily targeted. The campaign primarily targets telecommunications, financial services, and consumer rewards sectors. It uses fake Cloudflare error 524 pages as decoys, revealing malicious content selectively based on geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. The infrastructure is partially hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain involves SMS lures leading to progressive credential harvesting and theft of complete credit card details including CVV codes.
Potential Impact
The campaign results in credential theft and financial fraud through the capture of complete credit card details, including CVV codes. It affects multiple sectors, predominantly telecommunications and financial services, across at least 72 countries with a strong focus on Latin America. The use of decoy error pages and selective targeting increases the likelihood of successful victim engagement and evasion of detection.
Mitigation Recommendations
As this is a social engineering campaign rather than a software vulnerability, no patch or official fix exists. Organizations should focus on user awareness training about smishing and phishing risks, especially regarding SMS messages impersonating trusted brands. Monitoring for and blocking known phishing domains and IP indicators associated with this campaign can help reduce exposure. The vendor advisory does not indicate any automated mitigation or patch. Defensive measures should be tailored to detect and respond to phishing attempts and credential harvesting activities.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/error-524-decoy-smishing/"]
- Adversary
- null
- Pulse Id
- 6a20299f34e4961fdaff1615
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip154.81.166.17 | — | |
ip43.159.168.186 | CC=US ASN=AS132203 tencent building kejizhongyi avenue | |
ip43.162.84.202 | CC=IN ASN=ASNone | |
ip43.165.6.36 | CC=SG ASN=ASNone | |
ip45.135.162.90 | CC=US ASN=AS46562 performive llc | |
ip47.82.154.2 | CC=US ASN=ASNone | |
ip8.222.134.149 | CC=SG ASN=ASNone |
Threat ID: 6a213f67e29bf47b5086e260
Added to database: 06/04/2026, 09:03:35 UTC
Last enriched: 06/04/2026, 09:18:29 UTC
Last updated: 07/30/2026, 20:16:25 UTC
Views: 211
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.