logo

Exploiting SMS: Threat Actors Use Social Engineering to Target Companies

ID: 46137107-b2a7-508b-a189-4b900c75a87a

STIX ID: report--46137107-b2a7-508b-a189-4b900c75a87a

Feed Name: Cofense Blog

Threat Score
50/100

Date Published: 2025-04-17

Date Updated: 2026-04-27

Author: Cofense

...
...

Cofense PDC observed a smishing campaign that sends urgent SMS messages containing a Google redirect to a malicious domain (resolveservicedesk.com) which impersonates ServiceNow to harvest credentials and fake MFA prompts. The report documents the SMS lure, redirect behavior, the phishing landing page, and provides observed infection and payload URLs with associated IP addresses to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.