PULSE NAME
Exposing a Global Smishing Operation Across 19 Countries: Governments, Postal Services, and Telecoms Targeted
WHITE AlienVault 2026-05-27 Modified: 2026-05-28
90
IOCs
HIGH VOLUME
A coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus has been exposed, originating from fraudulent SMS messages impersonating Romania's government payment portal Ghișeul.ro. Investigation revealed 1,628 malicious URLs linked by a single 128-character campaign identifier, targeting government portals, traffic police departments, postal services including DPD and SEUR, tax authorities, and telecommunications providers like T-Mobile and Vodafone. The infrastructure utilizes 32 backend IP addresses distributed across Tencent Cloud, Alibaba Cloud, Cloudflare CDN, and ALEXHOST Moldova. Threat actors employ two distinct phishing templates: a Vue.js single-page application and a Bootstrap-based clone, executing a four-stage credential harvesting process that collects complete payment card details through fabricated traffic fines, toll payments, and delivery notifications.
Indicators of Compromise (11 / 90 total)
All FileHash-MD5 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
hostname dpd.ie-com.vip 2026-05-27
hostname e-uprava.gov-si.shop 2026-05-27
hostname e.csdd.govlv.cam 2026-05-27
hostname hoiatustrahv.politsei.gov-ee.bond 2026-05-27
hostname mvr.govmk.cam 2026-05-27
hostname mvr.govmk.one 2026-05-27
hostname sumin.lrv-lt.shop 2026-05-27
hostname www.ghiseul-ro.bond 2026-05-27
hostname www.ghiseul-ro.cfd 2026-05-27
hostname www.ghiseul.govro.one 2026-05-27
hostname www.ghiseulro.cyou 2026-05-27