SentinelOne reported that Xeon Sender, a Python-based cloud attack tool, is being used to send bulk SMS spam and smishing messages through legitimate APIs at multiple SaaS messaging providers using stolen or otherwise valid customer credentials. The tool was first observed in 2022 and has since been repeatedly rebranded by different threat actors, while retaining largely the same codebase and functionality across versions.
Xeon Sender supports nine SMS providers and includes features for credential checking, phone number validation, and number generation, enabling operators to automate large-scale message delivery through provider-specific libraries or crafted HTTP requests. Researchers said the activity reflects abuse of compromised accounts rather than software flaws in the providers, and highlighted defensive indicators including anomalous SMS permission changes, recipient list uploads, and suspicious API activity such as GetSMSAttributes and SetSMSAttributes in AWS environments.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-07, SentinelOne published a report detailing Xeon Sender's support for nine SMS providers, credential-checking and phone-number utilities, and its use of provider-specific libraries or crafted HTTP requests. The report also stated that the abuse stemmed from compromised accounts rather than vulnerabilities in the providers.
After its initial appearance, Xeon Sender was repeatedly rebranded by different threat actors while retaining little meaningful code divergence across versions. It was distributed through Telegram channels, cybercrime forums, and a hosted web GUI.
SentinelOne reported that the Python-based Xeon Sender cloud attack tool was first observed in 2022. The tool was used to send bulk SMS spam and smishing messages through legitimate APIs of SaaS messaging providers using stolen or otherwise valid credentials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.