#infobloxthreatintel — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #infobloxthreatintel, aggregated by home.social.
-
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
-
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
-
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
-
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
-
Solicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
-
One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?
A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.
The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.
Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.
There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.
hmtraff[.]com
d[.]gosmartdecision[.]comFinal landing page: https://urlscan.io/result/019f14b2-c99e-7677-a742-61f7c814b545/
Prior report: https://www.infoblox.com/blog/threat-intelligence/hold-the-phone-international-revenue-share-fraud-driven-by-fake-captchas/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf
-
Stolen phones - and specifically iPhones - have robust anti-theft protections. They are worthless once they're flagged - locked to their owner. So why are millions still being stolen every year?
In this paper, we uncover a thriving underground marketplace focused on unlocking stolen phones. It is powered by:Lookalike domains impersonating Apple, Xiaomi, Samsung and other brands
Smishing campaigns targeting device owners
Pay‑as‑you‑go “unlocking” tools sold on Telegram
By pivoting on DNS data, we identified 10,000+ malicious domains and a growing ecosystem turning locked devices into profit at scale.👉 Read how this supply chain works—from theft to resale—and why it’s growing fast. https://www.infoblox.com/blog/threat-intelligence/lookalike-domains-expose-the-iphone-theft-economy/
#ThreatIntel #CyberSecurity #Phishing #MobileSecurity #iOS #Smishing #dns #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel
-
📱Smishing Slows, Quishing Quickens 🎣
Sick of smishing and those pesky parking/toll texts? Don’t get caught by crafty, counterfeit court QR codes — it’s a scan-and-scam! 💳 🚨
North American cell phone users are being hit with yet another wave of smishing campaigns that now include quishing elements. Likely orchestrated by Chinese-speaking threat actors, this latest campaign builds on previous vehicular violations, evolving tactics while impersonating US courts. 🧑⚖️
We’ve recently seen a flurry of SMS messages pushing parking violations — but with a twist: face justice in court… or scan and pay instead!
Delivered as an official-looking image, the actor has begun integrating QR codes into these lures to help mask suspicious phishing URLs, baiting victims into entering personal information, credentials, and ultimately making payments.
For some, this lure may sound better than facing justice for their perceived poor parking. Victims who don't comply are warned that failure to appear or pay could have serious repercussions - a scare tactic designed to push you toward a hasty decision and scanning the QR code! 🫣
We uncovered thousands of these nefarious domains, through their use of Registered Domain Generation Algorithms (RDGAs) and local government impersonation, hosted across a diverse range of hosting providers to evade takedown.
Recent examples:
⛔ ahfgx[.]icu
⛔ euoyq[.]icu
⛔ htpze[.]icu
⛔ mwlaj[.]icuFriendly reminder - courts don't usually communicate with you via text. That said, we suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving tradecraft used in smishing and quishing delivery. As for us, we'll take our chances on evading that bench warrant and running from the law. 🏃♂️➡️
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #smishing #quishing
-
Smishy New Year: Fake Rewards, Real Scams!
Redeemed those "expiring" cell network reward points and awaiting your shiny new iPad or cash rebate?
⚠️📵 Think again. There's a catch - and your payment card details are on the hook! 🎣 💳
Cell phone users in North America are getting hit with yet another wave of smishing campaigns, likely orchestrated by Chinese-speaking threat actors. This campaign builds on previous toll scams, evolving tactics and expanding targets. Over the holidays and well into the New Year, a barrage of SMS messages have posed as banks and cell phone networks, dangling phishing links to bait customers with fake points and high value rewards about to expire.
Talk about FOMO! 💰🤑
But you already know how this one plays out. Victims are prompted to enter payment details for “verification” or “shipping” and the only ones being rewarded are those taking the payments.
We uncovered thousands of these nefarious domains through their use of Registered Domain Generation Algorithms (RDGAs) and brand impersonation, hosted across a diverse range of hosting providers to evade takedown.
Recent examples:
⛔ anzrewardsprogram2026d[.]cc
⛔ <brand>.dvqlp[.]icu
⛔ <brand>.outdz[.]icu
⛔ <brand>.xqufa[.]cc
⛔ <brand>rewards.734726[.]comWe suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving the tradecraft used in smishing delivery. As for us, we'll keep tracking til we get that iPad... 🙈
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #telecom #china