Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

University of Michigan dumps private safety after reporting surveillance

What is Zero Waste? FySelf Unveils the Eco-Friendly Lifestyle Revolution

Crypto CEO linked to Russia accused of $500 million laundry

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » The power of China’s Smithing Kits targets users in eight states, widespread toll fraud campaigns
Identity

The power of China’s Smithing Kits targets users in eight states, widespread toll fraud campaigns

userBy userApril 18, 2025No Comments5 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Chinese Smithing Kit

Cybersecurity researchers have warned of a “wide and continuous” SMS phishing campaign since mid-October 2024 that has been targeting US toll road users for financial theft.

“The toll road smishing attacks are being carried out by multiple financially motivated threat actors using the Smishing Kit developed by “Wang Duo Yu”, Cisco Talos researchers Azim Khodjibaev, Chetan Raghuprasad and Joey Chen.

A phishing campaign, for each company, impersonates a US electronic fee collection system such as E-ZPass, sends SMS messages and Apple Imessages to individuals in Washington, Florida, Pennsylvania, Virginia, Texas, Ohio, Illinois, Kansas, and clicks on fake links sent in the chat.

It is worth noting that in January 2025, several aspects of the fee phishing campaign were previously highlighted by security journalist Brian Krebs. The activity dates back to a China-based SMS phishing service called Lighthouse, advertised on Telegram.

Apple Imessage automatically disables links for messages received from unknown senders, but Smishing text encourages recipients to respond with “Y” to activate links, a tactic observed in phishing kits such as Darcula and Xiūgǒu.

Cybersecurity

If the victim clicks a link to access the domain, they will be asked to resolve a fake image-based Captcha Challenge.[.lcom” or “e-zpass[.]com-etcjr[.]xin”) They will be asked to access the invoice by entering their name and zip code.

The target is then asked to go further and make a payment on another fraudulent page. At that point, all entered personal and financial information will be sucked up by the threat actor.

Talos noted that multiple threat actors are likely to utilize the phishing kit developed by Wang Duo Yu, which has led to a similar Smishing kit being observed in use by another Chinese organized cybercrime group known as Smishing Triad.

Interestingly, Wang Duo Yu is said to be the creator of the phishing kit used by Smishing Triad, according to security researcher Grant Smith. “The creator is a current computer science student in China and uses the skills he is learning to make quite a penny on the side,” Smith revealed in an extensive analysis in August 2024.

Smishing Triad is known for carrying out a massive smishing attack targeting postal services in at least 121 countries, using failed package delivery lures to share message recipients and clicking fake links requesting personal and financial information under the guise of RedLeilivery’s expected service fees.

Additionally, threat actors using these kits attempted to register victim card details in their mobile wallets and used a technique known as Ghost Tap to allow them to further cash their funds at scale.

The phishing kit is known to be backed by the fact that the captured credit/debit card information is also extracted by creators, a technique known as double theft.

“Wang Duo Yu creates and designs specific smishing kits and sells access to these kits through telegram channels,” Talos said. “The kit offers a variety of infrastructure options, with full feature developments priced at $50 each, proxy development (if the customer has a personal domain and server), $20 for version updates and $20 for all other support.”

As of March 2025, the e-crime group is believed to be focusing their efforts on new lighthouse fishing kits aimed at harvesting qualifications from banks and financial institutions in Australia and Asia-Pacific, according to Silent Push.

Threat officials also claim they have “over 300 front desk staff” to support various aspects of the fraud and cash-out schemes associated with phishing kits.

“Smishing Triad sells phishing kits to other malicious threat actors through Telegram and possibly other channels,” the company said. “These sales make it difficult to attribute kits to any subgroup, so now all sites belong here under the Smithing Triad umbrella.”

Cybersecurity

In a report released last month, Prodaft revealed that Lighthouse shares tactical overlap with phishing kits such as Lucid and Darcula, and operates independently of Xinxin Group, the cybercriminal group behind the Lucid kit. The Swiss Cybersecurity Company tracks Wang Duo Yu (aka Lao Wang) as the Larva-241.

“An analysis of the attacks carried out using the Mid and Dacula panels revealed that the Lighthouse (Laowan/Wan Duo Yu) shares important similarities with the Xinxin group in terms of targeting, landing pages and domain creation patterns,” Prodaft said.

The return of the cybersecurity company was the first to record the Smithing Triad in 2023, saying it also tracks fraudulent toll campaigns. The Smithing Syndicate uses more than 60,000 domain names, and said it would be difficult for Apple and Google to block fraudulent activities in an effective way.

“With underground bulk SMS services, cybercriminals can expand their operations and target millions of users simultaneously,” Resecurity said. “These services allow attackers to efficiently send thousands or millions of fraudulent IM messages, targeting users or groups of users individually based on specific demographics in different regions.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFSU Shooting: What We Know About the Victims and Assault Allegations | Crime News
Next Article Trump EPA targets two geographic engineering startups to “pollution the air”
user
  • Website

Related Posts

More than 70 organizations in multiple sectors targeted by China-linked cyberspy groups

June 9, 2025

Two different botnets exploiting a vulnerability in Wazuh Server to launch a Mirai-based attack

June 9, 2025

Chrome 0-Day, Data Wipers, Misused Tools and Zero-Click iPhone Attacks

June 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

University of Michigan dumps private safety after reporting surveillance

What is Zero Waste? FySelf Unveils the Eco-Friendly Lifestyle Revolution

Crypto CEO linked to Russia accused of $500 million laundry

Guardiola will receive another honor in Manchester. This is from that university

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

IONQ acquires nearly $1.1 billion in British quantum startup Oxford Ionics

aixuspeed reports $500,000 in token commitments within the first 72 hours prior to sale

Vantage raises 720 million euros in the first ever euro ABS transaction backed by European data centres

Meta of lectures investing more than $100 billion in Silicon Valley’s top AI startups

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.