The Package That Never Shipped: Following a USPS Smishing Kit Through DNS Data
June 15, 2026, 4:15 p.m.
Description
A sophisticated smishing campaign impersonates United States Postal Service (USPS) package delivery notifications via SMS. The kit serves genuine USPS production HTML, CSS, fonts, and images verbatim, including live Google Analytics tags firing to USPS infrastructure. It captures victim card data in real-time through WebSocket connections, streaming keystrokes, performing server-side BIN lookups, and pushing routing decisions back to victim browsers. Starting from a single lure hostname, passive DNS analysis revealed 682 unique lookalike domains across seven Tencent Cloud hosts. A parallel UPS-themed campaign runs on the same infrastructure, with both variants sharing the internal theme name us_post_ups in cookies. The operation spans two distinct backends (GoFrame and Spring Boot) while maintaining identical real-time exfiltration mechanics and Caddy reverse proxy architecture.
Tags
Date
- Created: June 13, 2026, 2:59 a.m.
- Published: June 13, 2026, 2:59 a.m.
- Modified: June 15, 2026, 4:15 p.m.
Indicators
- 8e5546c83d764e1287b55cbe868a45344a6f0afa9782d798d03b2b7cfc53ec38
- 4fe8bec780537aa223406965415c1f85e83eec1f4e2181cf82e2a7b7516026e6
- http://xupqrnn.one/us?__theme_site_ticket=
- https://usps.xupqnqz.one/uqjmw
Additional Informations
- usps.xupqnqz.one
- xupqnqz.one
- xupqrnn.one
- gwrpfjx.life