logo

China-based SMS Phishing Triad Pivots to Banks

ID: ceec2190-d865-52cd-b7fd-56febe1e21c2

STIX ID: report--ceec2190-d865-52cd-b7fd-56febe1e21c2

Feed Name: Krebs on Security

Threat Score
75/100

Date Published: 2025-04-10

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

The report details the "Smishing Triad," a loosely federated set of China-based phishing-as-a-service operators that use iMessage and RCS to phish payment card data, enroll stolen cards into Apple and Google Wallets via one-time SMS/OTP interception, and cash out using device farms and NFC-relay apps; the actors run massive rotating domain fleets (~25,000 domains per 8 days), employ hundreds of support staff, and have inflicted global financial fraud at scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.