PULSE NAME
Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns
WHITE AlienVault 2026-04-29 Modified: 2026-05-29
24
IOCs
MEDIUM VOLUME
Since January 2025, researchers identified over 2,500 phishing domains targeting more than 70 organizations across financial services, telecommunications, and logistics sectors globally. Two dominant smishing campaigns were discovered: Reward Points phishing impersonating banks and telecom providers, and Failed Parcel Delivery phishing mimicking logistics companies. Despite different themes, both campaigns share infrastructure and utilize the Phoenix System administrative panel, a successor to the Mouse System. This Phishing-as-a-Service platform offers real-time victim monitoring, geofencing, IP-based filtering, and live-phishing interventions to bypass multi-factor authentication. The platform is distributed via Telegram channels for approximately $2,000 annually, providing threat actors with pre-built templates, traffic filtering mechanisms, and real-time victim management dashboards. Attackers potentially leverage fake Base Transceiver Stations to bypass carrier-level filtering and deliver messages app...
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (15 / 24 total)
All IPv4 URL
TYPEINDICATORDESCRIPTIONCREATED
IPv4 43.154.31.214 CC=HK ASN=AS132203 tencent building kejizhongyi avenue 2026-05-04
IPv4 43.156.61.150 CC=SG ASN=AS132203 tencent building kejizhongyi avenue 2026-05-04
IPv4 8.220.190.2 CC=SG ASN=ASNone 2026-05-04
IPv4 101.32.186.29 CC=HK ASN=AS132203 tencent building kejizhongyi avenue 2026-05-04
IPv4 156.245.145.174 CC=HK ASN=AS134548 dxtl tseung kwan o service 2026-05-04
IPv4 156.245.146.210 CC=HK ASN=AS134548 dxtl tseung kwan o service 2026-05-04
IPv4 23.95.166.127 CC=US ASN=AS36352 colocrossing 2026-05-04
IPv4 43.134.12.32 CC=SG ASN=AS132203 tencent building kejizhongyi avenue 2026-05-04
IPv4 43.134.239.46 CC=SG ASN=AS132203 tencent building kejizhongyi avenue 2026-05-04
IPv4 43.163.100.238 CC=SG ASN=ASNone 2026-05-04
IPv4 47.80.64.106 CC=US ASN=ASNone 2026-05-04
IPv4 47.80.70.114 CC=US ASN=ASNone 2026-05-04
IPv4 47.80.79.203 CC=US ASN=ASNone 2026-05-04
IPv4 8.212.128.102 CC=SG ASN=AS45102 alibaba (us) technology co. ltd. 2026-05-04
IPv4 8.220.130.133 CC=SG ASN=ASNone 2026-05-04