A new mass-scale SMS phishing (smishing) campaign has been found, attacking iMessage users through more than 10,000 newly registered domains. The domains impersonate toll services and package delivery websites, mostly in several U.S. states and a Canadian province. The attacker behind the campaign tricks victims into divulging personal and financial data. The domains, with their naming style being uniform and beginning with "com-," are highly structured to appear genuine at first glance. Two of these domains are "com-2h98[.]xin" and "com-courtfees[.]xin," intended to deceive victims during routine URL checks. The smishing messages utilize these spoofed domains to impersonate reputable services such as DHL, FedEx, and local toll services to make them even more authentic. For instance, domains such as "dhl.com-new[.]xin" and "ezdrive.com-2h98[.]xin" look like duplicates of names of reputable delivery companies and toll services. The spoofed domains affect users in at least ten U.S. states—California, Florida, Illinois, Kansas, Massachusetts, Pennsylvania, New Jersey, New York, Texas, and Virginia—and Ontario, Canada. To bypass the default link-blocking function of iMessage for non-contacts, the smishing messages tell the victims to respond with "Y," which recreates the messaging chain and allows the malicious links in. The trick manages to bypass iMessage's protection and put the victims at risk. More than 70% of the registered domains share the same two name servers, which are hosted by big providers such as Cloudflare, making it difficult to block the malicious traffic. The campaign has been aptly named "com_smishing" by researchers, and they are in constant monitoring and blocking the scammer domains. The complex attack of this sort again reiterates the ever-changing sophistication of smishing campaigns and underscores the necessity for improved cybersecurity awareness and defensive practices for safeguarding users from such attacks.
IBM released security patches for over 100 vulnerabilities across various products. The biggest sufferers of these patches were Storage Defender, for which patches were issued for ...
Fieldtex Products, a U.S.-based provider of contract sewing and medical supply fulfillment, has reported a data breach following an attack attributed to a well-known ransomware ope...
The Pierce County Library System (PCLS) has announced a major data breach affecting more than 340,000 individuals, including library patrons, employees, former employees, and some ...