logo

Researchers track surge in high-level Smishing Triad activity

ID: 48ce2ac9-e0d9-504b-9db3-d6181f1f3c1c

STIX ID: report--48ce2ac9-e0d9-504b-9db3-d6181f1f3c1c

Feed Name: CyberScoop

Threat Score
70/100

Date Published: 2025-10-23

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Researchers at Palo Alto Networks’ Unit 42 uncovered a large, China-managed smishing campaign called “Smishing Triad” that has generated roughly 195,000 malicious domains since January 2024. The operation leverages a decentralized ecosystem (domain sellers, phishing-kit developers, data brokers, spammers) to impersonate services across critical sectors—toll roads, postal services, finance, healthcare, law enforcement, and social media—harvesting national IDs, addresses, credentials and financial data via short-lived, frequently changing domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.