The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
ID: 7b97f26e-42fb-5746-a36f-086f27135e1c
STIX ID: report--7b97f26e-42fb-5746-a36f-086f27135e1c
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-10-23
Date Updated: 2026-04-28
Author: Reethika Ramesh, Zhanhao Chen, Daiping Liu, Chi-Wei Liu, Shehroze Farooqi and Moe Ghasemisharif
Executive Summary — Palo Alto Networks Unit 42 attributes a large, global smishing campaign to the Smishing Triad that leverages a phishing-as-a-service ecosystem to churn hundreds of thousands of short-lived domains impersonating toll services, mail carriers, banks, government agencies and other brands; the campaign uses SMS/RCS/IM delivery, visual phishing pages to harvest credentials and sensitive PII, and centralized DNS/registrar patterns while hosting infrastructure is concentrated in popular U.S. cloud providers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
