logo

Unraveling the U.S. toll road smishing scams

ID: bb73849a-6f72-50ae-90ce-84273e9e3f7c

STIX ID: report--bb73849a-6f72-50ae-90ce-84273e9e3f7c

Feed Name: Cisco Talos

Threat Score
60/100

Date Published: 2025-04-10

Date Updated: 2026-04-27

Author: Azim Khodjibaev

...
...

**Executive Summary:** Cisco Talos observed an ongoing smishing campaign impersonating U.S. toll operators since October 2024 that uses typosquatted domains and fake payment pages to steal card and personal details across multiple states; Talos links the kit used to a developer known as "Wang Duo Yu," documents the threat actor's Telegram/YouTube infrastructure and marketplace activity, and publishes associated IOCs and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.