BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-Linked Smishing Triad Hits 194K+ Domains in Global Scam

Global Smishing Campaign Registers Over 194,000 Malicious Domains Since 2024, Targeting Brokerage Accounts and Using Phishing-as-a-Service Network

  • More than 194,000 malicious domains linked to a global smishing campaign have been registered since January 2024.
  • The attack infrastructure primarily uses U.S.-hosted cloud services but is registered through a Hong Kong-based registrar.
  • The China-linked group called the Smishing Triad is behind the campaign, exploiting fake toll violation and delivery notices.
  • Phishing kits from this group are increasingly targeting brokerage accounts to steal banking credentials and authentication codes.
  • The campaign involves a phishing-as-a-service network including kit developers, domain sellers, spammers, and Hosting providers operating worldwide.

Since January 1, 2024, malicious actors linked to a widespread smishing campaign have registered over 194,000 harmful domains worldwide. According to findings from Palo Alto Networks Unit 42, the attack targets various services globally with domains mainly registered via a Hong Kong-based registrar but hosted on U.S. cloud platforms.

- Advertisement -

The group identified behind these operations, known as the Smishing Triad and believed to have ties to China, sends fraudulent messages about unpaid tolls or missed deliveries to prompt victims into revealing sensitive data. These schemes have generated more than $1 billion over three years, reports The Wall Street Journal.

A recent report by Fortra highlights a rise in attacks using phishing kits from the same group that now focus on brokerage accounts. This shift has caused a fivefold increase in such attacks in the second quarter of 2025 compared to the previous year. Security researcher Alexis Ober noted, “Once compromised, attackers manipulate stock market prices using ‘ramp and dump’ tactics,” which leave little evidence and increase financial risk.

Unit 42’s research explains that the smishing campaign operates as a large, decentralized “phishing-as-a-service” (PhaaS) ecosystem. This includes kit developers who create phishing tools, data brokers selling phone numbers, domain registrars for disposable sites, hosting providers managing servers, spammers distributing messages, and scanners verifying active phone numbers and avoiding detection.

Nearly 93,200 root domains are registered with Dominet (HK) Limited, and many domains exist for only a few days to evade security measures. The domains resolve to over 43,000 unique IP addresses, mostly hosted in the U.S. on Cloudflare services. The most impersonated service is the U.S. Postal Service with 28,045 domains, followed by toll services with about 90,000 dedicated phishing sites.

- Advertisement -

Phishing messages often redirect victims to fake landing pages claiming traffic or delivery fines, sometimes prompting users to run malicious code disguised as CAPTCHA verification. According to Unit 42, “The smishing campaign impersonating U.S. toll services is not isolated. It is instead a large-scale campaign with global reach, impersonating many services across different sectors.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

New Ukraine Cyberattack Targets Government, Healthcare Data

Ukraine's CERT-UA exposed a malware campaign targeting government and healthcare bodies, culminating in a...

Errol Musk Reveals Elon, Kimbal Own $1.6B in Bitcoin

Errol Musk revealed that his sons, Elon and Kimbal, hold approximately $1.6 billion in...

Ether ETF Inflows Hit $248M Despite Bearish Futures

Institutional accumulation via ETH ETFs and Bitmine Immersion is supporting a spot-driven price recovery...

Hackers Weaponize AI Platform n8n for Phishing Campaigns

Threat actors are weaponizing the popular AI workflow automation platform n8n to conduct phishing...

Fake Ledger App on Apple Store Steals $9.5M in Crypto

Apple removed a fraudulent Ledger wallet app after an investigation revealed it was used...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading