Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages
June 4, 2026, 9:08 a.m.
Description
A sophisticated smishing and phishing operation active since the second half of 2025 has impersonated over 267 brands across 72 countries, with particular concentration in Latin America. The campaign generated 4,389 phishing domain instances, with Mexico accounting for 1,851 cases. Telecommunications is the most targeted sector with 1,754 instances, followed by financial services and consumer rewards programs. The operation employs fake Cloudflare error pages as decoys, revealing malicious content only to victims matching specific geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. Approximately 30% of infrastructure is hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain progresses from SMS lures through progressive credential harvesting, ultimately capturing complete credit card details including CVV codes.
Tags
Date
- Created: June 3, 2026, 1:18 p.m.
- Published: June 3, 2026, 1:18 p.m.
- Modified: June 4, 2026, 9:08 a.m.
Indicators
- 154.81.166.17
- 8.222.134.149
- 43.159.168.186
- 47.82.154.2
- 43.162.84.202
- 43.165.6.36
- 45.135.162.90
Additional Informations
- Finance
- Transport
- Telecommunications
- Retail
- Government
- Colombia
- Netherlands
- Australia
- Germany
- Chile
- Mexico