DMV-Themed Phishing Campaign Targeting U.S. Citizens
June 23, 2025, 11:15 p.m.
Description
A sophisticated phishing campaign impersonating U.S. state Departments of Motor Vehicles emerged in May 2025, using SMS phishing and deceptive websites to harvest personal and financial data. Victims received messages about unpaid toll violations, directing them to fake DMV sites requesting extensive information. Technical analysis revealed shared infrastructure, consistent domain naming, and indicators of a China-based threat actor. The campaign used spoofed SMS numbers, often from the Philippines, and email addresses from obscure domains. Phishing websites followed a pattern using state IDs and specific TLDs. Infrastructure analysis showed connections to known malicious IP addresses and Chinese DNS providers. The campaign's widespread impact prompted alerts from multiple states and federal authorities.
Tags
Date
- Created: June 20, 2025, 7:26 p.m.
- Published: June 20, 2025, 7:26 p.m.
- Modified: June 23, 2025, 11:15 p.m.
Indicators
- e88b894cc69c4f4ec5f6fdb2e7a0314601241571bf02154412c0168973fdc4df
- 94126506523ebbf35ec9689f593d061453ab39395bf63098464dcbc270ee7f48
- 5df0fcc2b6b3d3e52fb635c0b7bac41d27b5b75cbfeb16c024d66a59657d5535
- 5c7b246ec5b654c6ba0c86c89ba5cbaa61d68536efc32283da7694ed8e70b16d
- 2f71a0956b7f073735dab092b0fb8e4c222538cf0a6bbdf7517a02ece6934157
- 288f3cb007f3ad99835a541b6be7e07f64aa7f7a56025518f02a1f0af41585b0
Additional Informations
- Government
- United States of America