home.social

#smishing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #smishing, aggregated by home.social.

  1. One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?

    A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.

    The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.

    Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.

    There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.

    hmtraff[.]com
    d[.]gosmartdecision[.]com

    Final landing page: urlscan.io/result/019f14b2-c99

    Prior report: infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf

  2. Stolen phones - and specifically iPhones - have robust anti-theft protections. They are worthless once they're flagged - locked to their owner. So why are millions still being stolen every year?
    In this paper, we uncover a thriving underground marketplace focused on unlocking stolen phones. It is powered by:

    Lookalike domains impersonating Apple, Xiaomi, Samsung and other brands
    Smishing campaigns targeting device owners
    Pay‑as‑you‑go “unlocking” tools sold on Telegram
    By pivoting on DNS data, we identified 10,000+ malicious domains and a growing ecosystem turning locked devices into profit at scale.

    👉 Read how this supply chain works—from theft to resale—and why it’s growing fast. infoblox.com/blog/threat-intel

    #ThreatIntel #CyberSecurity #Phishing #MobileSecurity #iOS #Smishing #dns #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel #threatintelligence #cybercrime  #infosec #infoblox #infobloxthreatintel

  3. 📱Smishing Slows, Quishing Quickens 🎣

    Sick of smishing and those pesky parking/toll texts? Don’t get caught by crafty, counterfeit court QR codes — it’s a scan-and-scam! 💳 🚨

    North American cell phone users are being hit with yet another wave of smishing campaigns that now include quishing elements. Likely orchestrated by Chinese-speaking threat actors, this latest campaign builds on previous vehicular violations, evolving tactics while impersonating US courts. 🧑‍⚖️

    We’ve recently seen a flurry of SMS messages pushing parking violations — but with a twist: face justice in court… or scan and pay instead!

    Delivered as an official-looking image, the actor has begun integrating QR codes into these lures to help mask suspicious phishing URLs, baiting victims into entering personal information, credentials, and ultimately making payments.

    For some, this lure may sound better than facing justice for their perceived poor parking. Victims who don't comply are warned that failure to appear or pay could have serious repercussions - a scare tactic designed to push you toward a hasty decision and scanning the QR code! 🫣

    We uncovered thousands of these nefarious domains, through their use of Registered Domain Generation Algorithms (RDGAs) and local government impersonation, hosted across a diverse range of hosting providers to evade takedown.

    Recent examples:
    ⛔ ahfgx[.]icu
    ⛔ euoyq[.]icu
    ⛔ htpze[.]icu
    ⛔ mwlaj[.]icu

    Friendly reminder - courts don't usually communicate with you via text. That said, we suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving tradecraft used in smishing and quishing delivery. As for us, we'll take our chances on evading that bench warrant and running from the law. 🏃‍♂️‍➡️

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #smishing #quishing

  4. Fate attenzione!
    È in corso una #truffa via SMS #smishing che sfrutta il nome Nexi (ma anche altre agenzie) per esfiltrare dati bancari.

    Messaggi allarmanti segnalano falsi pagamenti, invitando a cliccare su link o richiamare numeri per bloccare i (finti) pagamenti notificati. Nella interazione si finisce su pagine di #phishing o a parlare con truffatori che chiedono codici OTP e credenziali.

    Non cliccate su niente, non richiamate nessuno, cancellate e bloccate!

  5. OpenAI has reported that a breach at Mixpanel exposed limited API-user metadata, including names, emails, coarse location, OS/browser details and IDs.

    This was not an OpenAI breach, and no chat content, credentials, API keys or payment data were exposed.

    The incident resulted from a smishing compromise of Mixpanel’s environment.

    OpenAI has fully removed Mixpanel and is conducting wider vendor audits.
    How concerned should teams be about metadata exposure at third-party analytics providers?

    Full Article: technadu.com/mixpanel-breach-e

    Follow us for more security coverage.
    #infosec #OpenAI #Mixpanel #databreach #smishing #securityincident #MFA #vendorsecurity #securitynews

  6. Next week, I'm speaking at #Saintcon about #phishing, #smishing, #quishing (all the -ishings) and propose a broad-based possible solution that could end this problem forever. Nothing big.

    If you're going to be there, you can find me in Track 2 at 2:30pm, or most of the rest of the time at the @SAINTCON @malwarevillage Community, where we will be hosting two of our contests (MARC I and BOMBE) and encouraging people to consider the field of malware analysis and threat research as a career.

    We also will have minibadges, both at #MalwareVillage and at the #Netcraft booth. If you're a #minibadge fan/collector, you aren't going to want to miss out on the Netcraft minibadge, which is awesome. Just drop by the booth to get a kit to build one. Tell them Spike sent ya.

    Until then, stay safe, and please tell everyone you know, don't click links to tax refunds or toll road fees you get on your phone.

    /END

    netcraft.com/blog/taxpayers-dr

  7. Text message scams (smishing) are on the rise — from fake deliveries to prize alerts.
    🚫 Don’t engage or click links from unknown senders. If a text looks suspicious, contact the company directly via official channels. When in doubt, delete & block. #CyberSecurityAwarenessMonth #Smishing