logo

Chinese-Backed Smishing Rings Scale Credential Theft via SMS and OTT Apps

ID: 0628b1dd-615d-57bd-bad8-4da247092ffa

STIX ID: report--0628b1dd-615d-57bd-bad8-4da247092ffa

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Mayura Kathir

...
...

This report describes the rapid global expansion of Chinese-language phishing-as-a-service (PhaaS) ecosystems that use SMS (smishing) and OTT messaging (iMessage, RCS) to deliver credential theft campaigns. Researchers observed organized, scalable operations leveraging SIM box infrastructure, centralized backend phishing frameworks, and affiliate models to run cross-border campaigns at industrial scale; the series of upcoming urlscan.io reports will provide deeper visibility into these operations and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.