Smishing Triad Impersonation Campaigns Expand Globally
ID: 36c27155-3827-592c-ac8d-e6b5a5ff91fb
STIX ID: report--36c27155-3827-592c-ac8d-e6b5a5ff91fb
Feed Name: Infosecurity Magazine (News)
Dark Atlas investigators uncovered a growing campaign of fraudulent domains impersonating Egyptian service providers (Fawry, Egypt Post, Careem) and global brands, tied to the Chinese-speaking Smishing Triad. Analysts used HTTP headers and Shodan to expose additional spoofed sites hosted in an AS block linked to Tencent, and found the group markets customizable smishing kits via Telegram. The advisory also warns of competition from Darcula, a large phishing-as-a-service platform (Darcula 3.0) that offers anti-detection, automation and card-cloning tools, increasing the scale and sophistication of global phishing operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
