Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages

0
Medium
Published: Wed Jun 03 2026 (06/03/2026, 13:18:23 UTC)
Source: AlienVault OTX General

Description

A global smishing and phishing campaign active since mid-2025 impersonates over 267 brands across 72 countries, heavily targeting Latin America. It uses fake Cloudflare error 524 pages as decoys, revealing malicious content only to victims based on geofencing and mobile device checks. The campaign generated 4,389 phishing domains, primarily targeting telecommunications, financial services, and consumer rewards sectors. Data exfiltration is conducted via encrypted WebSocket channels with binary payloads. The attack chain starts with SMS lures and progresses to credential harvesting, ultimately stealing full credit card details including CVV codes. Approximately 30% of the infrastructure is hosted on Tencent Cloud and Alibaba US servers, masked by Cloudflare. The campaign affects countries including Australia, Chile, Colombia, Germany, Mexico, and the Netherlands. No official patch or fix is applicable as this is a social engineering campaign rather than a software vulnerability.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/04/2026, 09:18:29 UTC

Technical Analysis

This is a sophisticated smishing and phishing operation active since the second half of 2025 that impersonates over 267 brands across 72 countries, with a concentration in Latin America. It generated 4,389 phishing domains, with Mexico heavily targeted. The campaign primarily targets telecommunications, financial services, and consumer rewards sectors. It uses fake Cloudflare error 524 pages as decoys, revealing malicious content selectively based on geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. The infrastructure is partially hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain involves SMS lures leading to progressive credential harvesting and theft of complete credit card details including CVV codes.

Potential Impact

The campaign results in credential theft and financial fraud through the capture of complete credit card details, including CVV codes. It affects multiple sectors, predominantly telecommunications and financial services, across at least 72 countries with a strong focus on Latin America. The use of decoy error pages and selective targeting increases the likelihood of successful victim engagement and evasion of detection.

Mitigation Recommendations

As this is a social engineering campaign rather than a software vulnerability, no patch or official fix exists. Organizations should focus on user awareness training about smishing and phishing risks, especially regarding SMS messages impersonating trusted brands. Monitoring for and blocking known phishing domains and IP indicators associated with this campaign can help reduce exposure. The vendor advisory does not indicate any automated mitigation or patch. Defensive measures should be tailored to detect and respond to phishing attempts and credential harvesting activities.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/error-524-decoy-smishing/"]
Adversary
null
Pulse Id
6a20299f34e4961fdaff1615
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip154.81.166.17
ip43.159.168.186
CC=US ASN=AS132203 tencent building kejizhongyi avenue
ip43.162.84.202
CC=IN ASN=ASNone
ip43.165.6.36
CC=SG ASN=ASNone
ip45.135.162.90
CC=US ASN=AS46562 performive llc
ip47.82.154.2
CC=US ASN=ASNone
ip8.222.134.149
CC=SG ASN=ASNone

Threat ID: 6a213f67e29bf47b5086e260

Added to database: 6/4/2026, 9:03:35 AM

Last enriched: 6/4/2026, 9:18:29 AM

Last updated: 6/4/2026, 12:48:57 PM

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses