Unraveling the U.S. toll road smishing scams
ID: bb73849a-6f72-50ae-90ce-84273e9e3f7c
STIX ID: report--bb73849a-6f72-50ae-90ce-84273e9e3f7c
Feed Name: Cisco Talos
Threat Score
**Executive Summary:** Cisco Talos observed an ongoing smishing campaign impersonating U.S. toll operators since October 2024 that uses typosquatted domains and fake payment pages to steal card and personal details across multiple states; Talos links the kit used to a developer known as "Wang Duo Yu," documents the threat actor's Telegram/YouTube infrastructure and marketplace activity, and publishes associated IOCs and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
