logo

Fake Shipment Tracking Scams Surge in MEA, Stealing Banking Data Through Real-Time Phishing

ID: b3e5ccba-a8c1-5cc7-a120-88a57c26ed6b

STIX ID: report--b3e5ccba-a8c1-5cc7-a120-88a57c26ed6b

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Group-IB observed a large-scale fake shipment tracking phishing campaign across the Middle East and Africa that uses SMS lures pointing to mobile-optimized counterfeit courier sites; the pages include embedded scripts that open WebSocket connections to exfiltrate keystrokes, including card data and OTPs, in real time. The report identifies targeted countries (notably Egypt), abused sectors (postal and financial services), attacker infrastructure patterns (disposable TLDs, shared IPs), links to the Darcula phishing-as-a-service ecosystem, and recommends user and provider mitigations such as avoiding SMS links, implementing DMARC/DKIM/SPF, and carrier-level SMS filtering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.