Full Report
While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) platform with real-time victim monitoring, geofencing, and live-phishing interventions to bypass multi-factor authentication.
Analysis Summary
# Tool/Technique: Phoenix System
## Overview
The **Phoenix System** is a sophisticated, centralized Phishing-as-a-Service (PhaaS) platform designed for large-scale smishing (SMS phishing) operations. It provides cybercriminals with a comprehensive administrative panel to manage global campaigns, monitor victims in real-time, and execute advanced maneuvers to bypass security measures like Multi-Factor Authentication (MFA). The platform is currently targeting regions across APAC, LATAM, Europe, and MEA.
## Technical Details
- **Type:** Phishing-as-a-Service (PhaaS) / Administrative Panel
- **Platform:** Web-based (Targeting mobile users via SMS/Smishing)
- **Capabilities:** Real-time monitoring, geofencing, MFA bypass, live interaction.
- **First Seen:** Reported in 2024 (Operational status indicates recent high activity).
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1566.002 - Phishing: Spearphishing Service]
- **[TA0007 - Discovery]**
- [T1614 - System Location Discovery] (via Geofencing)
- **[TA0006 - Credential Access]**
- [T1556.006 - Modify Authentication Process: Multi-Factor Authentication Bypass]
- [T1111 - Adversary-in-the-Middle]
- **[TA0011 - Command and Control]**
- [T1071.001 - Application Layer Protocol: Web Protocols]
## Functionality
### Core Capabilities
- **Centralized Admin Panel:** Provides a unified interface for threat actors to manage multiple phishing templates and campaigns simultaneously.
- **Real-time Victim Monitoring:** Attackers can see exactly when a victim interacts with the phishing link, providing live updates on data entry.
- **Geofencing:** Restricts access to phishing pages based on the victim’s IP address or geographic location, helping to evade detection by automated security scanners and researchers outside the target region.
- **Credential Harvesting:** Specifically designed to capture login credentials, personally identifiable information (PII), and financial data.
### Advanced Features
- **Live-Phishing Interventions:** Allows attackers to manually intervene during a live session to request additional information from the victim.
- **MFA Bypass:** Capable of intercepting One-Time Passwords (OTPs) and 2FA tokens in real-time. The panel prompts the victim for their code, which the attacker immediately uses on the legitimate service.
- **BTS Injection Support:** While the system is a panel, it is designed to work alongside advanced SMS delivery methods such as Base Transceiver Station (BTS) injection and bulk messaging gateways.
## Indicators of Compromise
### Network Indicators
*Note: All indicators have been defanged.*
- **C2 / Admin Infrastructure IPs:**
- 23[.]95[.]166[.]127
- 38[.]162[.]114[.]0
- 43[.]133[.]0[.]0
- 43[.]134[.]0[.]0
- 43[.]134[.]12[.]32
- 43[.]134[.]239[.]46
- 43[.]154[.]31[.]214
- 43[.]156[.]61[.]150
- 43[.]163[.]100[.]238
- 47[.]80[.]64[.]106
- 47[.]80[.]70[.]114
- 47[.]80[.]79[.]203
- 8[.]212[.]128[.]102
- 8[.]220[.]130[.]133
- 8[.]220[.]190[.]2
- 101[.]32[.]186[.]29
- 156[.]245[.]145[.]174
- 156[.]245[.]146[.]210
## Associated Threat Actors
- **Phoenix System Operators:** Specific groups are currently categorized by the use of this specific PhaaS platform; operations are global, suggesting multiple affiliates.
## Detection Methods
- **Behavioral Detection:** Monitoring for unusual login patterns (e.g., immediate login attempts from a new IP following a user's interaction with an SMS link).
- **Network Monitoring:** Flagging traffic to known Phoenix System infrastructure IPs and domains associated with smishing templates.
- **SMS Filtering:** Implementing security solutions that scan SMS content for high-risk URLs and domain spoofing.
## Mitigation Strategies
- **User Education:** Training employees and customers to recognize smishing tactics and the risks of clicking links in unsolicited SMS messages.
- **Hardware Security Keys:** Moving away from SMS-based OTPs toward FIDO2/WebAuthn-compliant hardware keys which are resistant to Adversary-in-the-Middle (AiTM) attacks.
- **IP Reputation:** Blocking traffic from known malicious IP ranges and hosting providers frequently abused by the Phoenix System.
- **Number Masking Awareness:** Cautioning users that "Official" sender names in SMS can be spoofed via BTS injection.
## Related Tools/Techniques
- **Adversary-in-the-Middle (AiTM):** General technique used by the Phoenix System to intercept credentials.
- **Smishing (SMS Phishing):** The primary delivery vector.
- **BTS Injection:** An advanced technique used to spoof legitimate sender IDs (Alphanumeric Senders) to make phishing texts appear authentic.