logo

Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages

ID: b37e7662-2da4-51dc-b883-3bcda9f5f5b0

STIX ID: report--b37e7662-2da4-51dc-b883-3bcda9f5f5b0

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

...
...

Group-IB documents a sophisticated, large-scale smishing/phishing campaign ("Smishing Error524") active since H2 2025 that impersonates 260+ brands across 72 countries—primarily targeting LATAM—and uses thousands of short-lived domains, Base64-encoded Single Page Applications, Cloudflare-styled decoy error pages (e.g., Error 524), geofencing/mobile-user filters, and encrypted WebSocket channels to exfiltrate personal data and full credit card credentials in real time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.