Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages
A global smishing and phishing campaign active since mid-2025 impersonates over 267 brands across 72 countries, heavily targeting Latin America. It uses fake Cloudflare error 524 pages as decoys, revealing malicious content only to victims based on geofencing and mobile device checks. The campaign generated 4,389 phishing domains, primarily targeting telecommunications, financial services, and consumer rewards sectors. Data exfiltration is conducted via encrypted WebSocket channels with binary payloads. The attack chain starts with SMS lures and progresses to credential harvesting, ultimately stealing full credit card details including CVV codes. Approximately 30% of the infrastructure is hosted on Tencent Cloud and Alibaba US servers, masked by Cloudflare. The campaign affects countries including Australia, Chile, Colombia, Germany, Mexico, and the Netherlands. No official patch or fix is applicable as this is a social engineering campaign rather than a software vulnerability.
AI Analysis
Technical Summary
This is a sophisticated smishing and phishing operation active since the second half of 2025 that impersonates over 267 brands across 72 countries, with a concentration in Latin America. It generated 4,389 phishing domains, with Mexico heavily targeted. The campaign primarily targets telecommunications, financial services, and consumer rewards sectors. It uses fake Cloudflare error 524 pages as decoys, revealing malicious content selectively based on geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. The infrastructure is partially hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain involves SMS lures leading to progressive credential harvesting and theft of complete credit card details including CVV codes.
Potential Impact
The campaign results in credential theft and financial fraud through the capture of complete credit card details, including CVV codes. It affects multiple sectors, predominantly telecommunications and financial services, across at least 72 countries with a strong focus on Latin America. The use of decoy error pages and selective targeting increases the likelihood of successful victim engagement and evasion of detection.
Mitigation Recommendations
As this is a social engineering campaign rather than a software vulnerability, no patch or official fix exists. Organizations should focus on user awareness training about smishing and phishing risks, especially regarding SMS messages impersonating trusted brands. Monitoring for and blocking known phishing domains and IP indicators associated with this campaign can help reduce exposure. The vendor advisory does not indicate any automated mitigation or patch. Defensive measures should be tailored to detect and respond to phishing attempts and credential harvesting activities.
Affected Countries
Australia, Chile, Colombia, Germany, Mexico, Netherlands
Indicators of Compromise
- ip: 154.81.166.17
- ip: 43.159.168.186
- ip: 43.162.84.202
- ip: 43.165.6.36
- ip: 45.135.162.90
- ip: 47.82.154.2
- ip: 8.222.134.149
Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages
Description
A global smishing and phishing campaign active since mid-2025 impersonates over 267 brands across 72 countries, heavily targeting Latin America. It uses fake Cloudflare error 524 pages as decoys, revealing malicious content only to victims based on geofencing and mobile device checks. The campaign generated 4,389 phishing domains, primarily targeting telecommunications, financial services, and consumer rewards sectors. Data exfiltration is conducted via encrypted WebSocket channels with binary payloads. The attack chain starts with SMS lures and progresses to credential harvesting, ultimately stealing full credit card details including CVV codes. Approximately 30% of the infrastructure is hosted on Tencent Cloud and Alibaba US servers, masked by Cloudflare. The campaign affects countries including Australia, Chile, Colombia, Germany, Mexico, and the Netherlands. No official patch or fix is applicable as this is a social engineering campaign rather than a software vulnerability.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This is a sophisticated smishing and phishing operation active since the second half of 2025 that impersonates over 267 brands across 72 countries, with a concentration in Latin America. It generated 4,389 phishing domains, with Mexico heavily targeted. The campaign primarily targets telecommunications, financial services, and consumer rewards sectors. It uses fake Cloudflare error 524 pages as decoys, revealing malicious content selectively based on geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. The infrastructure is partially hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain involves SMS lures leading to progressive credential harvesting and theft of complete credit card details including CVV codes.
Potential Impact
The campaign results in credential theft and financial fraud through the capture of complete credit card details, including CVV codes. It affects multiple sectors, predominantly telecommunications and financial services, across at least 72 countries with a strong focus on Latin America. The use of decoy error pages and selective targeting increases the likelihood of successful victim engagement and evasion of detection.
Mitigation Recommendations
As this is a social engineering campaign rather than a software vulnerability, no patch or official fix exists. Organizations should focus on user awareness training about smishing and phishing risks, especially regarding SMS messages impersonating trusted brands. Monitoring for and blocking known phishing domains and IP indicators associated with this campaign can help reduce exposure. The vendor advisory does not indicate any automated mitigation or patch. Defensive measures should be tailored to detect and respond to phishing attempts and credential harvesting activities.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/error-524-decoy-smishing/"]
- Adversary
- null
- Pulse Id
- 6a20299f34e4961fdaff1615
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip154.81.166.17 | — | |
ip43.159.168.186 | CC=US ASN=AS132203 tencent building kejizhongyi avenue | |
ip43.162.84.202 | CC=IN ASN=ASNone | |
ip43.165.6.36 | CC=SG ASN=ASNone | |
ip45.135.162.90 | CC=US ASN=AS46562 performive llc | |
ip47.82.154.2 | CC=US ASN=ASNone | |
ip8.222.134.149 | CC=SG ASN=ASNone |
Threat ID: 6a213f67e29bf47b5086e260
Added to database: 6/4/2026, 9:03:35 AM
Last enriched: 6/4/2026, 9:18:29 AM
Last updated: 6/4/2026, 12:48:57 PM
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.