Skip to main content

Threats Tagged 'smishing'

View all threats tagged with 'smishing'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: smishing

Threats Tagged 'smishing'

Click on any threat for detailed analysis and mitigation recommendations

Since early May 2026, a large-scale phishing campaign has targeted individuals with fraudulent text messages claiming their T-Mobile rewards points are about to expire. The messages create urgency by stating that point balances, typically cited as 18,400 points, will expire imminently if not redeemed. Recipients are directed to click on phishing links using rotating domains designed to mimic legitimate T-Mobile websites. The campaign has generated over 1,000 closely related message templates with only superficial variations in salutations, dates, and point balances. The operation experienced two major spikes in activity before declining. The criminals employed at least 81 domains over four months, all following a recognizable pattern. These messages use generic greetings and formal language to appear legitimate, exploiting social engineering tactics to trick recipients into divulging login credentials, personal information, or payment details.

Join the discussion

An active SMS phishing campaign targets Serbian road users by impersonating Putevi Srbije, Serbia's state road authority. Victims receive text messages claiming they have unpaid traffic fines with urgent payment demands. The fraudulent links lead to cloned government websites designed to steal payment card details. The infrastructure employs JavaScript-based obfuscation techniques to evade automated security scanners and uses disposable domains with uncommon TLDs. Technical analysis reveals connections to both Darcula and Phoenix Phishing-as-a-Service platforms, indicating fraudsters are combining tools from multiple PhaaS vendors. The operation demonstrates coordinated roles including infrastructure setup, SMS distribution, and data harvesting. Similar campaigns have targeted victims globally across government bodies, postal services, and financial institutions.

Join the discussion

With the introduction of charges/taxes on certain items posted from outside the EU, threat actors appear to be leveraging the situation to send fraudulent SMS and email messages impersonating postal services in an attempt to harvest payment details and personal information. The campaign is already being observed targeting Irish users, and I'd like to highlight this activity publicly as part of a LinkedIn post around our Brand Protection, Threat Intelligence, and Domain Takedown capabilities.

Join the discussion

A sophisticated smishing and phishing operation active since the second half of 2025 has impersonated over 267 brands across 72 countries, with particular concentration in Latin America. The campaign generated 4,389 phishing domain instances, with Mexico accounting for 1,851 cases. Telecommunications is the most targeted sector with 1,754 instances, followed by financial services and consumer rewards programs. The operation employs fake Cloudflare error pages as decoys, revealing malicious content only to victims matching specific geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. Approximately 30% of infrastructure is hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain progresses from SMS lures through progressive credential harvesting, ultimately capturing complete credit card details including CVV codes.

Join the discussion

A coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus has been exposed, originating from fraudulent SMS messages impersonating Romania's government payment portal Ghișeul.ro. Investigation revealed 1,628 malicious URLs linked by a single 128-character campaign identifier, targeting government portals, traffic police departments, postal services including DPD and SEUR, tax authorities, and telecommunications providers like T-Mobile and Vodafone. The infrastructure utilizes 32 backend IP addresses distributed across Tencent Cloud, Alibaba Cloud, Cloudflare CDN, and ALEXHOST Moldova. Threat actors employ two distinct phishing templates: a Vue.js single-page application and a Bootstrap-based clone, executing a four-stage credential harvesting process that collects complete payment card details through fabricated traffic fines, toll payments, and delivery notifications.

Join the discussion

Since January 2025, researchers identified over 2,500 phishing domains targeting more than 70 organizations across financial services, telecommunications, and logistics sectors globally. Two dominant smishing campaigns were discovered: Reward Points phishing impersonating banks and telecom providers, and Failed Parcel Delivery phishing mimicking logistics companies. Despite different themes, both campaigns share infrastructure and utilize the Phoenix System administrative panel, a successor to the Mouse System. This Phishing-as-a-Service platform offers real-time victim monitoring, geofencing, IP-based filtering, and live-phishing interventions to bypass multi-factor authentication. The platform is distributed via Telegram channels for approximately $2,000 annually, providing threat actors with pre-built templates, traffic filtering mechanisms, and real-time victim management dashboards. Attackers potentially leverage fake Base Transceiver Stations to bypass carrier-level filtering and deliver messages app...

Join the discussion

Frogblight is a medium-severity Android banking Trojan primarily targeting users in Turkey. It masquerades as legitimate apps, initially as a court case file viewer and later as common apps like Chrome, to trick victims into installation. The malware steals banking credentials via official government websites and has extensive spyware capabilities, including SMS interception, app enumeration, device info collection, and sending arbitrary SMS messages. It employs advanced persistence and anti-deletion techniques and is distributed mainly through smishing campaigns exploiting legal concerns. Although currently focused on Turkey, its sophisticated remote control features and ongoing development pose risks if it spreads. No CVSS score exists, but the threat impacts confidentiality and integrity significantly with moderate ease of exploitation and no user interaction beyond initial install. European organizations with Turkish-speaking users or business ties should monitor for potential spillover. Mitigations include user education on smishing, app installation restrictions, SMS monitoring, and enhanced mobile endpoint protection.

Join the discussion

A large-scale smishing campaign, attributed to the China-based Smishing Triad, is targeting global users with fraudulent SMS messages impersonating toll violations and package delivery issues. The campaign has expanded internationally, targeting critical sectors such as banking, healthcare, and law enforcement by using realistic phishing pages to harvest sensitive data. It operates via a decentralized infrastructure with over 194,000 malicious domains registered since early 2024, primarily through a Hong Kong-based registrar. This phishing-as-a-service operation leverages sophisticated social engineering to maximize victim engagement. The campaign poses a significant threat to individuals and organizations worldwide, including European entities, due to the broad targeting and sector diversity. No known exploits in the wild have been reported, but the scale and complexity indicate a persistent and evolving threat. Defenders should focus on advanced SMS filtering, user awareness, and domain monitoring to mitigate risks. The threat is assessed as medium severity given its impact on confidentiality and ease of exploitation without requiring authentication but does not directly affect system availability.

Join the discussion

The Jingle Thief campaign, conducted by financially motivated threat actors from Morocco, targets global enterprises in retail and consumer services sectors to execute gift card fraud. Using phishing and smishing tactics, the attackers gain access to Microsoft 365 environments, exploiting cloud services for reconnaissance, lateral movement, and persistence. They focus on compromising gift card issuance systems, leveraging internal documentation and communication channels. The campaign demonstrates sophisticated techniques, including tailored phishing, internal email manipulation, and device registration abuse. The attackers maintain long-term access, sometimes over a year, making detection challenging. Their activities often align with holiday periods to maximize impact.

Join the discussion

A sophisticated phishing campaign impersonating U.S.state Departments of Motor Vehicles emerged in May 2025, using SMS phishing and deceptive websites to harvest personal and financial data. Victims received messages about unpaid toll violations, directing them to fake DMV sites requesting extensive information. Technical analysis revealed shared infrastructure, consistent domain naming, and indicators of a China-based threat actor. The campaign used spoofed SMS numbers, often from the Philippines, and email addresses from obscure domains. Phishing websites followed a pattern using state IDs and specific TLDs. Infrastructure analysis showed connections to known malicious IP addresses and Chinese DNS providers. The campaign's widespread impact prompted alerts from multiple states and federal authorities.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: smishing
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses