← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns
Since January 2025, researchers identified over 2,500 phishing domains targeting more than 70 organizations across financial services, telecommunications, and logistics sectors globally. Two dominant smishing campaigns were discovered: Reward Points phishing impersonating banks and telecom providers, and Failed Parcel Delivery phishing mimicking logistics companies. Despite different themes, both campaigns share infrastructure and utilize the Phoenix System administrative panel, a successor to the Mouse System. This Phishing-as-a-Service platform offers real-time victim monitoring, geofencing, IP-based filtering, and live-phishing interventions to bypass multi-factor authentication. The platform is distributed via Telegram channels for approximately $2,000 annually, providing threat actors with pre-built templates, traffic filtering mechanisms, and real-time victim management dashboards. Attackers potentially leverage fake Base Transceiver Stations to bypass carrier-level filtering and deliver messages app...
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| IPv4 | 43.154.31.214 | CC=HK ASN=AS132203 tencent building kejizhongyi avenue | 2026-05-04 | |
| IPv4 | 43.156.61.150 | CC=SG ASN=AS132203 tencent building kejizhongyi avenue | 2026-05-04 | |
| IPv4 | 8.220.190.2 | CC=SG ASN=ASNone | 2026-05-04 | |
| IPv4 | 101.32.186.29 | CC=HK ASN=AS132203 tencent building kejizhongyi avenue | 2026-05-04 | |
| IPv4 | 156.245.145.174 | CC=HK ASN=AS134548 dxtl tseung kwan o service | 2026-05-04 | |
| IPv4 | 156.245.146.210 | CC=HK ASN=AS134548 dxtl tseung kwan o service | 2026-05-04 | |
| IPv4 | 23.95.166.127 | CC=US ASN=AS36352 colocrossing | 2026-05-04 | |
| IPv4 | 43.134.12.32 | CC=SG ASN=AS132203 tencent building kejizhongyi avenue | 2026-05-04 | |
| IPv4 | 43.134.239.46 | CC=SG ASN=AS132203 tencent building kejizhongyi avenue | 2026-05-04 | |
| IPv4 | 43.163.100.238 | CC=SG ASN=ASNone | 2026-05-04 | |
| IPv4 | 47.80.64.106 | CC=US ASN=ASNone | 2026-05-04 | |
| IPv4 | 47.80.70.114 | CC=US ASN=ASNone | 2026-05-04 | |
| IPv4 | 47.80.79.203 | CC=US ASN=ASNone | 2026-05-04 | |
| IPv4 | 8.212.128.102 | CC=SG ASN=AS45102 alibaba (us) technology co. ltd. | 2026-05-04 | |
| IPv4 | 8.220.130.133 | CC=SG ASN=ASNone | 2026-05-04 |
References (1)