{"id":7941,"date":"2025-10-25T10:03:28","date_gmt":"2025-10-25T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/25\/new-text-message-based-phishing-attack-from-china-targeting-users-around-the-globe\/"},"modified":"2025-10-25T10:03:28","modified_gmt":"2025-10-25T10:03:28","slug":"new-text-message-based-phishing-attack-from-china-targeting-users-around-the-globe","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/25\/new-text-message-based-phishing-attack-from-china-targeting-users-around-the-globe\/","title":{"rendered":"New Text Message Based Phishing Attack from China Targeting Users Around the Globe"},"content":{"rendered":"<p>    New Text Message Based Phishing Attack from China Targeting Users Around the Globe<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated text message phishing campaign originating from China has emerged as one of the most extensive cybersecurity threats targeting users worldwide.<\/p>\n<p>The operation, attributed to a threat collective known as the Smishing Triad, represents a massive escalation in SMS-based fraud, impersonating services across banking, healthcare, law enforcement, e-commerce, and government sectors.<\/p>\n<p>What began as isolated incidents of toll violation notices has evolved into a coordinated global campaign affecting users in over 121 countries.<\/p>\n<p>Palo Alto Networks analysts identified the campaign\u2019s unprecedented scale through comprehensive threat intelligence gathering.<\/p>\n<p>Their research uncovered 194,345 fully qualified domain names spanning 136,933 root domains registered since January 2024.<\/p>\n<p>The attack infrastructure demonstrates remarkable sophistication, with threat actors registering and cycling through thousands of domains daily to evade detection mechanisms.<\/p>\n<p>The majority of these <a href=\"https:\/\/cybersecuritynews.com\/new-luna-moth-domains-attacking-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">domains<\/a> flow through Dominet (HK) Limited, a Hong Kong-based registrar, while utilizing Chinese nameservers for DNS infrastructure.<\/p>\n<p>However, the actual hosting infrastructure concentrates within U.S. cloud services, particularly within autonomous system AS13335 on the 104.21.0.0\/16 subnet.<\/p>\n<p>The campaign\u2019s delivery mechanisms have undergone significant transformation. Early attacks employed email-to-SMS features through iMessage, but threat actors have recently transitioned to direct phone number-based delivery.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgVVx2dTdI5qmXrAVZlQj-lJ3XaZOv0DxnWK8OQEj1KM5_Du2auTvmwDX_SBBSeF1syNS9bOj-yNRpHxMQllKaAEiifQI16RfMdvkZGkoCecswy0HLE7vr85kmqQPhtJ0h6jYg_vdGhLOJ2sjKiWTLqIw2TBrMjD-jgDqqz11sRHeoJzazvLiifGDgTki8\/s16000\/The%2520PhaaS%2520ecosystem%2520of%2520the%2520Smishing%2520Triad%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">The PhaaS ecosystem of the Smishing Triad (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>Messages predominantly originate from Philippine international codes (+63) and U.S. numbers (+1), creating an illusion of legitimacy.<\/p>\n<p>The phishing messages themselves employ sophisticated <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> tactics, incorporating targeted personal information and technical jargon to establish urgency and credibility.<\/p>\n<p>Palo Alto Networks researchers <a href=\"https:\/\/unit42.paloaltonetworks.com\/global-smishing-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the operation functions as a comprehensive Phishing-as-a-Service ecosystem operating through Telegram channels.<\/p>\n<p>Analysis of the Smishing Triad\u2019s communication networks revealed a highly specialized supply chain with distinct roles.<\/p>\n<p>Data brokers sell target phone numbers, domain sellers register disposable domains, and hosting providers maintain backend infrastructure.<\/p>\n<p>Phishing kit developers create frontend interfaces and <a href=\"https:\/\/cybersecuritynews.com\/hackers-harvesting-office-365-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential harvesting<\/a> dashboards, while SMS spammers deliver messages at scale.<\/p>\n<p>Supporting roles include liveness scanners verifying active phone numbers and blocklist scanners monitoring domain reputation to trigger rapid asset rotation.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-underground-infrastructure-and-domain-lifecycle\"><strong>Underground Infrastructure and Domain Lifecycle<\/strong><\/h2>\n<p>The campaign\u2019s infrastructure exhibits remarkable resilience through decentralization and rapid domain cycling.<\/p>\n<p>Palo Alto Networks analysts observed that 29.19 percent of domains remain active for two days or less, with 71.3 percent lasting under one week.<\/p>\n<p>Domain naming conventions typically follow hyphenated string patterns like gov-addpayment.info or com-posewxts.top, deliberately crafted to deceive casual inspection.<\/p>\n<p>The Telegram chat records shows various underground service providers competing within the <a href=\"https:\/\/cybersecuritynews.com\/new-voidproxy-phaas-service\/\" target=\"_blank\" rel=\"noreferrer noopener\">PhaaS<\/a> ecosystem.<\/p>\n<p>While the interconnected infrastructure reveals how 90 different root domains route through concentrated IP address clusters within Cloudflare\u2019s network infrastructure.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-text-message-based-phishing-attack\/\">New Text Message Based Phishing Attack from China Targeting Users Around the Globe<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-text-message-based-phishing-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Text Message Based Phishing Attack from China Targeting Users Around the Globe A sophisticated text message phishing campaign originating from China has emerged as one of the most extensive cybersecurity threats targeting users worldwide. The operation, attributed to a threat collective known as the Smishing Triad, represents a massive escalation in SMS-based fraud, impersonating [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7941","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7941"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7941"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7941\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}