BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-Linked Smishing Triad Hits 194K+ Domains in Global Scam

Global Smishing Campaign Registers Over 194,000 Malicious Domains Since 2024, Targeting Brokerage Accounts and Using Phishing-as-a-Service Network

  • More than 194,000 malicious domains linked to a global smishing campaign have been registered since January 2024.
  • The attack infrastructure primarily uses U.S.-hosted cloud services but is registered through a Hong Kong-based registrar.
  • The China-linked group called the Smishing Triad is behind the campaign, exploiting fake toll violation and delivery notices.
  • Phishing kits from this group are increasingly targeting brokerage accounts to steal banking credentials and authentication codes.
  • The campaign involves a phishing-as-a-service network including kit developers, domain sellers, spammers, and Hosting providers operating worldwide.

Since January 1, 2024, malicious actors linked to a widespread smishing campaign have registered over 194,000 harmful domains worldwide. According to findings from Palo Alto Networks Unit 42, the attack targets various services globally with domains mainly registered via a Hong Kong-based registrar but hosted on U.S. cloud platforms.

- Advertisement -

The group identified behind these operations, known as the Smishing Triad and believed to have ties to China, sends fraudulent messages about unpaid tolls or missed deliveries to prompt victims into revealing sensitive data. These schemes have generated more than $1 billion over three years, reports The Wall Street Journal.

A recent report by Fortra highlights a rise in attacks using phishing kits from the same group that now focus on brokerage accounts. This shift has caused a fivefold increase in such attacks in the second quarter of 2025 compared to the previous year. Security researcher Alexis Ober noted, “Once compromised, attackers manipulate stock market prices using ‘ramp and dump’ tactics,” which leave little evidence and increase financial risk.

Unit 42’s research explains that the smishing campaign operates as a large, decentralized “phishing-as-a-service” (PhaaS) ecosystem. This includes kit developers who create phishing tools, data brokers selling phone numbers, domain registrars for disposable sites, hosting providers managing servers, spammers distributing messages, and scanners verifying active phone numbers and avoiding detection.

Nearly 93,200 root domains are registered with Dominet (HK) Limited, and many domains exist for only a few days to evade security measures. The domains resolve to over 43,000 unique IP addresses, mostly hosted in the U.S. on Cloudflare services. The most impersonated service is the U.S. Postal Service with 28,045 domains, followed by toll services with about 90,000 dedicated phishing sites.

- Advertisement -

Phishing messages often redirect victims to fake landing pages claiming traffic or delivery fines, sometimes prompting users to run malicious code disguised as CAPTCHA verification. According to Unit 42, “The smishing campaign impersonating U.S. toll services is not isolated. It is instead a large-scale campaign with global reach, impersonating many services across different sectors.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Flare’s XRP DeFi falters with 80 daily users, FLR hits all-time low

Flare Network's bridged XRP DeFi ecosystem averages fewer than 80 new users daily since...

Citi Sees 140% Upside for Circle Stock

Citi analysts reiterated a Buy rating on Circle (CRCL) with a $243 price target,...

UK sanctions crypto marketplace Xinbi over scam center ties

The UK sanctioned cryptocurrency marketplace Xinbi, a major illicit platform in Southeast Asia, for...

MARA sells $1.1B in Bitcoin to slash debt

MARA Holdings sold 15,133 Bitcoin for roughly $1.1 billion to fund a major debt...

Coinbase, Better Launch Crypto-Backed Mortgage Down Payments

Coinbase and Better Home & Finance launched a structure allowing qualified borrowers to pledge...

Must Read

14 Ways On How to Make Money with Cryptocurrency

Many people want to make money with cryptocurrency because they have heard the success stories of people who became millionaires from zero.If you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading