CERT-AGID warned of new smishing campaigns impersonating Italy’s INPS, using the agency’s name, logo, and branding to lure victims to fraudulent websites that harvest personal information and payment card data. Investigators observed at least two visual variants of the fake pages and different requested payment amounts, indicating the operators may be testing which lure performs better while maintaining the same core objective of credential and financial theft.
Separate infrastructure analysis tied the INPS-themed activity to a broader phishing operation built on newly registered lookalike domains such as inps names on low-cost TLDs including .cfd, .sbs, .bond, and .buzz. Pivoting from four Tencent-hosted IP addresses and shared traits such as cloned login portals, root-path 404 behavior, and GoFrame HTTP Server fingerprints expanded the cluster from 19 recent INPS-themed domains to 148 domains associated with 196 scans and impersonation of 25 brands across roughly a dozen countries, suggesting an organized actor reusing the same playbook beyond the Italian government theme.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
CERT-AGID identified new smishing campaigns impersonating INPS through use of its name, logo, and branding to steal personal information and payment card data via malicious websites. The fraudulent sites appeared in two graphic variants and requested different payment amounts, suggesting possible A/B testing by the operators.
Because many of the domains had previously gone unflagged or unscanned, the researchers submitted all 148 domains to urlscan with phishing-related tags to improve visibility and detection.
By pivoting on four Tencent IP addresses, researchers expanded the cluster from 19 recent INPS-themed domains to 148 unique domains tied to 196 scans and impersonation of 25 brands across about a dozen countries. Links involving trenitalia.id and trenitalla.id suggested overlap with a previously documented campaign and likely reuse of the same actor playbook.
An investigation starting from newly registered domains resembling Italy's INPS brand found cloned login portals, root-path 404 behavior, GoFrame HTTP Server fingerprints, and hosting on Tencent AS132203, indicating an organized phishing operation rather than isolated registrations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecarlesi.vg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.