PULSE NAME
Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns
WHITE AlienVault 2026-04-29 Modified: 2026-05-29
24
IOCs
MEDIUM VOLUME
Since January 2025, researchers identified over 2,500 phishing domains targeting more than 70 organizations across financial services, telecommunications, and logistics sectors globally. Two dominant smishing campaigns were discovered: Reward Points phishing impersonating banks and telecom providers, and Failed Parcel Delivery phishing mimicking logistics companies. Despite different themes, both campaigns share infrastructure and utilize the Phoenix System administrative panel, a successor to the Mouse System. This Phishing-as-a-Service platform offers real-time victim monitoring, geofencing, IP-based filtering, and live-phishing interventions to bypass multi-factor authentication. The platform is distributed via Telegram channels for approximately $2,000 annually, providing threat actors with pre-built templates, traffic filtering mechanisms, and real-time victim management dashboards. Attackers potentially leverage fake Base Transceiver Stations to bypass carrier-level filtering and deliver messages app...
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (9 / 24 total)
All IPv4 URL
TYPEINDICATORDESCRIPTIONCREATED
URL http://154.91.90.0 2026-05-04
URL http://38.162.114.0 2026-05-04
URL http://43.133.0.0 2026-05-04
URL http://43.134.0.0 2026-05-04
URL http://43.153.0.0 2026-05-04
URL http://43.160.192.0 2026-05-04
URL http://43.162.0.0 2026-05-04
URL http://45.203.220.0 2026-05-04
URL http://47.80.0.0 2026-05-04