Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages
ID: b37e7662-2da4-51dc-b883-3bcda9f5f5b0
STIX ID: report--b37e7662-2da4-51dc-b883-3bcda9f5f5b0
Feed Name: Group-IB Blog
Threat Score
Group-IB documents a sophisticated, large-scale smishing/phishing campaign ("Smishing Error524") active since H2 2025 that impersonates 260+ brands across 72 countries—primarily targeting LATAM—and uses thousands of short-lived domains, Base64-encoded Single Page Applications, Cloudflare-styled decoy error pages (e.g., Error 524), geofencing/mobile-user filters, and encrypted WebSocket channels to exfiltrate personal data and full credit card credentials in real time.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
