logo

Smishing Triad Impersonation Campaigns Expand Globally

ID: 36c27155-3827-592c-ac8d-e6b5a5ff91fb

STIX ID: report--36c27155-3827-592c-ac8d-e6b5a5ff91fb

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-11-25

Date Updated: 2026-04-22

...
...

Dark Atlas investigators uncovered a growing campaign of fraudulent domains impersonating Egyptian service providers (Fawry, Egypt Post, Careem) and global brands, tied to the Chinese-speaking Smishing Triad. Analysts used HTTP headers and Shodan to expose additional spoofed sites hosted in an AS block linked to Tencent, and found the group markets customizable smishing kits via Telegram. The advisory also warns of competition from Darcula, a large phishing-as-a-service platform (Darcula 3.0) that offers anti-detection, automation and card-cloning tools, increasing the scale and sophistication of global phishing operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.