logo

The Smishing Deluge: China-Based Campaign Flooding Global Text Messages

ID: 7b97f26e-42fb-5746-a36f-086f27135e1c

STIX ID: report--7b97f26e-42fb-5746-a36f-086f27135e1c

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2025-10-23

Date Updated: 2026-04-28

Author: Reethika Ramesh, Zhanhao Chen, Daiping Liu, Chi-Wei Liu, Shehroze Farooqi and Moe Ghasemisharif

...
...

Executive Summary — Palo Alto Networks Unit 42 attributes a large, global smishing campaign to the Smishing Triad that leverages a phishing-as-a-service ecosystem to churn hundreds of thousands of short-lived domains impersonating toll services, mail carriers, banks, government agencies and other brands; the campaign uses SMS/RCS/IM delivery, visual phishing pages to harvest credentials and sensitive PII, and centralized DNS/registrar patterns while hosting infrastructure is concentrated in popular U.S. cloud providers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.