Full Report
Los investigadores de Group-IB exponen una operación de smishing y phishing a gran escala que suplanta más de 260 marcas en 72 países, utilizando páginas de error 524 falsas para evadir el análisis.
Analysis Summary
# Incident Report: Global Smishing Operation Using False "Error 524" Evasion
## Executive Summary
Group-IB researchers have identified a large-scale, automated smishing and phishing operation targeting over 260 brands across 72 countries. The campaign utilizes sophisticated evasion techniques, specifically mimicking Cloudflare "Error 524" pages to deceive automated scanners and security researchers. The primary goal is the mass theft of personally identifiable information (PII) and financial credentials through localized fraudulent pages.
## Incident Details
- **Discovery Date:** 2024 (Ongoing research)
- **Incident Date:** Active campaign observed throughout 2024
- **Affected Organization:** Over 260 brands (Telecom, Postal Services, Banking)
- **Sector:** Multi-sector (Logistics, Finance, Telecommunications)
- **Geography:** Global (72 countries, including significant activity in LATAM, EU, and APAC)
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing
- **Vector:** SMS (Smishing) and potentially instant messaging.
- **Details:** Victims receive localized SMS messages containing shortened links or domains mimicking legitimate brand names (e.g., postal delivery failures or account verification alerts).
### Lateral Movement
- **N/A:** As this is a phishing/fraud operation, movement is not within a corporate network but involves redirecting victims through a series of traffic distribution systems (TDS).
### Data Exfiltration/Impact
- **Details:** The operation captures full names, residential addresses, phone numbers, credit card details (CVV, expiry), and one-time passwords (OTP) via real-time phishing panels.
### Detection & Response
- **Detection:** Identified by Group-IB’s Digital Risk Protection and Threat Intelligence systems through behavioral analysis of "Error 524" pages.
- **Response Actions:** Mapping of C2 infrastructure, identification of backend servers (Tencent/Alibaba), and notification to affected brand owners and hosting providers for takedown efforts.
## Attack Methodology
- **Initial Access:** Smishing (SMS Phishing) using bulk messaging gateways.
- **Persistence:** High-volume registration of domains on low-cost TLDs (.ink, .bond, .top).
- **Defense Evasion:**
- **Geofencing:** Restricting access to victims from specific IP ranges/countries.
- **Bot Detection:** Displaying a fake "Cloudflare Error 524" (A timeout error) to non-target IPs, automated scanners, and researchers.
- **CDN Masking:** Use of Cloudflare to hide the origin IP addresses of the phishing servers.
- **Credential Access:** Harvesting PII and Credit Card data via man-in-the-middle phishing panels.
- **Discovery:** Fingerprinting victim user-agents and browser headers to serve the appropriate localized exploit kit.
- **Impact:** Financial fraud and identity theft.
## Impact Assessment
- **Financial:** High potential for direct financial loss via unauthorized credit card transactions and OTP interception.
- **Data Breach:** Massive volume of PII stolen globally across 260+ brands.
- **Operational:** High volume of fraudulent customer support inquiries for impersonated brands.
- **Reputational:** Damage to brand trust for the 260+ companies being spoofed.
## Indicators of Compromise
### Network Indicators
- 47.82.154[.]2
- 43.165.6[.]36
- 43.159.168[.]186
- 154.81.166[.]17
- 43.162.84[.]202
- 8.222.134[.]149
- 45.135.162[.]90
### Behavioral Indicators
- Sequential naming patterns for domains (e.g., brand-service-update[.]top).
- Unsolicited SMS messages with urgent calls to action regarding delivery or banking.
- Unexpected "Error 524" pages when visiting suspicious links from non-mobile devices or VPNs.
## Response Actions
- **Containment:** Blocked identified IoCs at the network perimeter.
- **Eradication:** Initiated takedowns of phishing domains via registrars and reported origin servers to Alibaba/Tencent.
- **Recovery:** Public awareness campaigns by affected brands to warn customers of smishing tactics.
## Lessons Learned
- **Evasion Evolution:** Threat actors are increasingly using "decoy errors" (like the fake 524 error) to make phishing sites appear broken to security tools while remaining active for victims.
- **Localization is Key:** The high success rate is attributed to the actors' ability to localize content for 72 different countries and 260 brands automatically.
## Recommendations
- **For Organizations:** Implement Digital Risk Protection (DRP) to monitor for domain squatting and brand impersonation.
- **For Consumers:** Never click on links in SMS messages. Always navigate directly to the official website of a service provider.
- **Technical:** Use advanced email and SMS filtering that can analyze shortened URLs and detect TDS (Traffic Distribution System) behavior.