Group-IB reported that the Smishing Error524 operation has run since the second half of 2025, expanding from Latin America to 72 countries while impersonating more than 267 brands across telecommunications, financial services, consumer rewards, government, and logistics. Investigators linked the campaign to at least 4,389 phishing domains, with Mexico the most heavily targeted country, followed by Chile and Colombia. The attack begins with SMS lures sent from local-looking numbers and shortened links, directing victims to phishing pages designed to harvest national identification numbers, personal details, and full payment card information.
The infrastructure uses a layered anti-analysis design that shows fake Cloudflare Error 524 pages to researchers, scanners, and other non-targeted visitors, while only users matching geofencing, mobile device, and session checks receive the malicious content. Group-IB said the phishing kit is an obfuscated Vue.js single-page application using Base64-encoded content and FormKit, with stolen data exfiltrated in real time over encrypted WebSocket channels and heartbeat telemetry. Operators also hid backend systems behind Cloudflare proxies and used origin hosting tied to Tencent Cloud and Alibaba Cloud, helping mask infrastructure and rotate domains quickly.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Group-IB reported that the Smishing Error524 smishing and phishing operation has been active since the second half of 2025, initially focusing on Latin America. The campaign used SMS lures and phishing infrastructure impersonating major brands to steal personal and payment data.
On June 5, 2026, Group-IB published findings on Smishing Error524, describing a campaign expanded to 72 countries, impersonating more than 267 brands, and using 4,389 phishing domains. The report detailed the operation's anti-analysis design, fake Cloudflare error-page decoys, and encrypted WebSocket-based data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.