home.social

#smishing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #smishing, aggregated by home.social.

  1. Received a text offering big money just to watch YouTube videos? 🛑 It’s a classic task scam designed to drain your bank account through psychological grooming and fake fees. Read the technical breakdown to stay protected! 📱🔒

    #Cybersecurity #TaskScam #Smishing

    bdking71.wordpress.com/2026/09

  2. One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?

    A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.

    The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.

    Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.

    There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.

    hmtraff[.]com
    d[.]gosmartdecision[.]com

    Final landing page: urlscan.io/result/019f14b2-c99

    Prior report: infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf

  3. Supuestos “mensajes urgentes” disparan casos de fraudes digitales, alerta UNED

    La casa de enseñanza señala que las estafas a través de smishing se han convertido en “una de las principales amenazas digitales” en 2026.
    La entrada Supuestos “mensajes urgentes” disparan casos de fraudes digitales, alerta UNED aparece primero en Semanario Universidad.

    #Ciberfraudes #Estafas #Fraudes #País #RolandoRojas #Smishing #Tecnología #Uned #UniversidadEstatalADistancia #ÚltimaHora

    semanariouniversidad.com/pais/

  4. 📹 DomainTools Solution Engineer Steven Behm shares how to use DomainTools passive DNS database, DNSDB, to find domains with patterns in their naming schemes.

    He begins by using DomainTools Iris Investigate to spot patterns at the apex level, domain level in the pivot engine, as well as the subdomain level in the pDNS panel.

    He then moves over to DomainTools Farsight DNSDB to query our passive DNS database, specifically using a regular expression (regex) query. This is technically a flexible search in DNSDB Scout, and he makes it as specific as possible to find more information.

    This helps security organizations stay ahead of emerging threats and reduce exposure to risk in an efficient, quick way.

    youtube.com/watch?v=R2Qsw4L5js

    #proactivesecurity #cybersecurity #smishing #phishing

  5. Another week, another newsletter - catch up on the week's infosec news here:

    opalsec.substack.com/p/soc-gou

    Researchers have found that nearly two years on, 2 in 3 installs of #Apache #Superset are still using default Flask Secret Keys - a configuration flaw which would allow an attacker to forge session cookies and access said servers with full administrative privileges.

    #Kritec is a commodity #skimmer found installed on compromised #Magecart sites, with its code heavily obfuscated and customised to match the site's aesthetic in order to con users out of credit card details.

    #FIN7 look to be popping instances of the #Veeam backup software that are unpatched for a recent vulnerability; a revised #ViperSoftX #infostealer now targets #1password and #keepass password vaults, and #TA505 deliver a new infostealer through a #GoogleAds campaign

    #LockBit & #CL0P ransomware affiliates have been abusing a month-old vulnerability in the #PaperCut print management software to drop ransomware. With the cat out of the bag, security researchers have decided now is a great time to drop a PoC exploit on Github - I mean, why not let the skiddies get in on the action too, right?

    The #blueteam have some great research worth reading on #Smishing via #AWS; detections for #SliverC2 and different implementations of #PsExec, as well as #Sigma integration for #SentinelOne and a #KQL hack for monitoring LOLDrivers.

    Have a great week ahead folks, I hope this newsletter proves helpful!

    opalsec.substack.com/p/soc-gou

    #infosec #cyber #news #newsletter #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #affiliate #dfir #soc #threatintel #threatintelligence #threathunting #detection #threatdetection #detectionengineering #flask #python #fraud #malvertising #clop #PoC #exploit #securityresearch #LOLBAS #LOLBIN #BYOVD