Hunt.io Traces Smishing Campaign Targeting Services in 19 Countries

· Original article ↗

Summary

Hunt.io traced a multi-country smishing campaign using 1,628 URLs to impersonate government, postal, telecom, and other services. Fake payment pages harvest card details; shared page fingerprints link the infrastructure.

Key points

  • Hunt.io identified 1,628 campaign-linked URLs targeting organizations and services across 19 countries in Europe, the Americas, and the Caucasus.
  • Lures impersonate government payment and traffic-fine portals, delivery services, telecoms, and other brands.
  • The phishing flow collects vehicle-registration details, invents fines or payment demands, then harvests cardholder names, card numbers, expiration dates, and CVVs.
  • Researchers linked the pages using a shared 128-character metadata identifier and matching JavaScript assets; the operation used two distinct phishing templates.
  • The mapped infrastructure included 32 backend IP addresses across Tencent Cloud, Alibaba Cloud, Cloudflare, and ALEXHOST.
  • The campaign was still active at the time of analysis; Hunt.io recommends monitoring the shared identifier and typosquatted domains, and warns users not to follow payment demands sent by SMS.

Article Details

Attack Vectors
  • Fraudulent SMS messages direct recipients to phishing sites impersonating government payment portals, road-police services, parcel-delivery companies, telecommunications providers, and other services.
  • The Romanian traffic-fine site requests a vehicle registration number, displays a fabricated fine with an urgent payment deadline, and collects the cardholder name, card number, expiration date, and CVV.
  • After card submission, a fake loading screen creates the appearance of payment processing while, according to the investigation, the card details are transmitted to attacker infrastructure.
  • The operators use lookalike and typosquatted domains. Most identified sites use a shared Vue.js phishing template; one Romanian toll-payment site uses a different, Bootstrap-based template.
Defensive Notes
  • Check the full URL against the service's official domain before entering information; copied branding and SSL-related claims do not establish legitimacy.
  • Treat SMS payment demands for fines or tolls that link to a website as suspicious. Ghișeul.ro states that it does not announce payment obligations by SMS or email.
  • Security teams can search page HTML for the 128-character metadata identifier documented in the article to find sites in the reported cluster.
  • Organizations whose brands are impersonated should monitor lookalike domain registrations, including registrations under .lat, .shop, .cyou, .bond, .sbs, and .cfd.

Indicators of compromise

TypeIndicatorContext
DOMAINdpd-lv[.]topPhishing domain using DPD delivery branding in the Latvia-targeted examples.
DOMAINdpd[.]ie-com[.]vipPhishing domain impersonating DPD delivery service in Ireland.
DOMAINdpde[.]latPhishing domain using DPD delivery branding in the Latvia-targeted examples.
DOMAINdpdlv[.]bondPhishing domain using DPD delivery branding in the Latvia-targeted examples.
DOMAINdsvag[.]sbsDSV-branded delivery or logistics phishing domain in the English-language examples.
DOMAINdsvav[.]cfdDSV-branded delivery or logistics phishing domain in the English-language examples.
DOMAINdsvcv[.]cfdDSV-branded delivery or logistics phishing domain in the English-language examples.
DOMAINdsvxk[.]cyouDSV-branded delivery or logistics phishing domain in the English-language examples.
DOMAINe-csddlv[.]topPhishing domain impersonating Latvian road-traffic services.
DOMAINfanveris[.]cyouPhishing domain listed among the Spain-targeted campaign examples.
DOMAINgobal-store-hub[.]shopDomain listed as part of the campaign's generic e-commerce phishing examples.
DOMAINgov-si[.]camPhishing domain impersonating Slovenia's e-Uprava.
DOMAINgov-si[.]qponPhishing domain impersonating Slovenia's e-Uprava.
DOMAINgov-si[.]sbsPhishing domain impersonating Slovenia's e-Uprava.
DOMAINgov-si[.]xinPhishing domain impersonating Slovenia's e-Uprava.
DOMAINgove[.]latPhishing domain impersonating Slovenia's e-Uprava.
DOMAINgovh[.]latPhishing domain impersonating Slovenia's e-Uprava.
DOMAINgovj[.]latPhishing domain impersonating Slovenia's e-Uprava.
DOMAINgovk[.]latPhishing domain impersonating Slovenia's e-Uprava.
DOMAINgovl[.]latPhishing domain impersonating Slovenia's e-Uprava.
DOMAINgovo[.]latPhishing domain impersonating Slovenia's e-Uprava.
DOMAINgovsi[.]barPhishing domain impersonating Slovenia's e-Uprava.
DOMAINmvr-gov-mk[.]cyouPhishing domain impersonating North Macedonia's MVR.
DOMAINmvr[.]latPhishing domain impersonating Bulgarian MVR traffic-fine services.
DOMAINmvrbg[.]inkPhishing domain impersonating Bulgarian MVR traffic-fine services.
DOMAINmvrbg[.]lifePhishing domain impersonating Bulgarian MVR traffic-fine services.
DOMAINmvrbg[.]sbsPhishing domain impersonating Bulgarian MVR traffic-fine services.
DOMAINmvrcc[.]latPhishing domain impersonating Bulgarian MVR traffic-fine services.
DOMAINmvri[.]latPhishing domain impersonating Bulgarian MVR traffic-fine services.
DOMAINmvrx[.]latPhishing domain impersonating Bulgarian MVR traffic-fine services.
DOMAINroadpolice-am[.]icuPhishing domain impersonating Armenian Road Police services.
DOMAINroadpolice-am[.]shopPhishing domain impersonating Armenian Road Police services.
DOMAINroadspolice[.]latPhishing domain impersonating Armenian Road Police services.
DOMAINseur-bcdef[.]ccPhishing domain impersonating SEUR.
DOMAINseur-cztwp[.]clubPhishing domain impersonating SEUR.
DOMAINseur-fghij[.]orgPhishing domain impersonating SEUR.
DOMAINseur-fqlap[.]cyouPhishing domain impersonating SEUR.
DOMAINseur-hijkl[.]ccPhishing domain impersonating SEUR.
DOMAINseur-hxrz[.]orgPhishing domain impersonating SEUR.
DOMAINseur-jwqec[.]linkPhishing domain impersonating SEUR.
DOMAINseur-rmvxq[.]clubPhishing domain impersonating Spanish parcel-delivery service SEUR.
DOMAINseur-rxkmd[.]cyouPhishing domain impersonating SEUR.
DOMAINseur-yzabc[.]comPhishing domain impersonating SEUR.
DOMAINseur-zkryw[.]cloudPhishing domain impersonating SEUR.
DOMAINtesco-redeem-check[.]bondPhishing domain impersonating Tesco rewards in the United Kingdom.
DOMAINvodafaone[.]shopPhishing domain impersonating Vodafone in Albania.
DOMAINworldmartonline[.]comDomain listed as part of the campaign's generic e-commerce phishing examples.
HOSTNAMEe-uprava[.]gov-si[.]shopPhishing hostname impersonating Slovenia's e-Uprava.
HOSTNAMEe[.]csdd[.]govlv[.]camPhishing hostname impersonating Latvian road-traffic services.
HOSTNAMEhoiatustrahv[.]politsei[.]gov-ee[.]bondPhishing hostname impersonating Estonian road-traffic or police services.
HOSTNAMEmvr[.]govmk[.]camPhishing hostname impersonating North Macedonia's MVR.
HOSTNAMEmvr[.]govmk[.]onePhishing hostname impersonating North Macedonia's MVR.
HOSTNAMEsumin[.]lrv-lt[.]shopPhishing hostname impersonating Lithuanian government services.
IPV443[.]153[.]72[.]244Tencent Cloud server in Santa Clara identified as hosting 72 domains in the reported infrastructure.
IPV443[.]157[.]122[.]50Tencent Cloud server identified in the phishing infrastructure's Frankfurt deployment.
IPV443[.]157[.]17[.]77Tencent Cloud server identified as a high-capacity phishing-infrastructure hub.
IPV443[.]157[.]25[.]170Tencent Cloud server identified as a high-capacity phishing-infrastructure hub.
IPV443[.]157[.]64[.]211Tencent Cloud server identified in the phishing infrastructure's Frankfurt deployment.
IPV443[.]157[.]91[.]129Tencent Cloud server identified in the phishing infrastructure's Frankfurt deployment.
IPV443[.]160[.]221[.]174Tencent Cloud server identified in the phishing infrastructure's Singapore deployment.
IPV443[.]160[.]242[.]3Tencent Cloud server identified in the phishing infrastructure's Singapore deployment.
IPV443[.]160[.]250[.]19Tencent Cloud server in the phishing infrastructure; the report says it hosts 25 domains.
IPV443[.]165[.]1[.]208Tencent Cloud server in the phishing infrastructure; the report says it serves nine domains.
IPV443[.]165[.]3[.]200Tencent Cloud server identified in the phishing infrastructure's Frankfurt deployment.
IPV443[.]165[.]4[.]234Tencent Cloud server identified in the phishing infrastructure's Frankfurt deployment.
IPV443[.]165[.]4[.]68Tencent Cloud server identified in the phishing infrastructure's Frankfurt deployment.
IPV443[.]165[.]62[.]39Tencent Cloud server identified in the phishing infrastructure's Frankfurt deployment.
IPV443[.]173[.]74[.]207Tencent Cloud server identified in the phishing infrastructure's Santa Clara deployment.
IPV447[.]245[.]142[.]76Alibaba Cloud server in Frankfurt identified as hosting phishing domains.
IPV447[.]254[.]147[.]205Alibaba Cloud server in Frankfurt identified as hosting phishing domains.
IPV447[.]91[.]88[.]57Alibaba Cloud server in Frankfurt identified as hosting phishing domains.
IPV480[.]96[.]58[.]119ALEXHOST server in Moldova identified as part of the phishing infrastructure.
IPV480[.]96[.]58[.]68ALEXHOST server in Moldova identified as part of the phishing infrastructure.
URLhxxp[:]//ghisaul[.]lat/roTyposquatted Romanian phishing URL sharing the campaign's JavaScript asset.
URLhxxp[:]//ghiseul-ro[.]cyou/Fraudulent URL impersonating Ghișeul.ro.
URLhxxp[:]//ghiseul-ro[.]sbs/Fraudulent URL impersonating Ghișeul.ro found in the crawler results.
URLhxxp[:]//ghiseul-ro[.]shop/Fraudulent URL impersonating Ghișeul.ro found in the crawler results.
URLhxxp[:]//ghiseul[.]cfd/payFraudulent Ghișeul.ro-themed payment URL.
URLhxxp[:]//ghiseul[.]eu[.]cc/payGhișeul.ro-impersonating URL using the distinct toll-payment phishing template.
URLhxxps[:]//ghiseal[.]lat/ro/Typosquatted Romanian phishing URL sharing the campaign's JavaScript asset.
URLhxxps[:]//ghiseal[.]lat/ro/#/indexRomanian traffic-fine phishing page that collects vehicle details and leads to card collection.
URLhxxps[:]//ghiseul[.]autos/ro/Fraudulent Romanian-language URL impersonating Ghișeul.ro.
URLhxxps[:]//ghiseul[.]cyou/payFraudulent Ghișeul.ro-themed payment URL.
URLhxxps[:]//ghisiul[.]lat/ro/Typosquatted Romanian phishing URL sharing the campaign's JavaScript asset.
URLhxxps[:]//ghizeul[.]lat/ro/Typosquatted Romanian phishing URL sharing the campaign's JavaScript asset.
URLhxxps[:]//www[.]ghiseul-ro[.]bond/ghiseul/public/Fraudulent URL mimicking the Ghișeul.ro portal path.
URLhxxps[:]//www[.]ghiseul-ro[.]cfd/ghiseul/public/Fraudulent URL mimicking the Ghișeul.ro portal path.
URLhxxps[:]//www[.]ghiseul[.]govro[.]one/ghiseul/public/Fraudulent URL mimicking the Ghișeul.ro portal path.
URLhxxps[:]//www[.]ghiseulro[.]cyou/ro/Fraudulent URL impersonating Ghișeul.ro.

MITRE ATT&CK

Vendors

Products

Tools

Countries

AlbaniaIreland, Spain, France, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (United States, Trinidad & Tobago), and the Caucasus (Georgia,Armeniawas also targeting DPD delivery customers in the UK and Ireland, road police portals in Bulgaria and Armenia, tax authorities in Greece, and T-Mobile users in the United States.Bulgariataxpayers was also targeting DPD delivery customers in the UK and Ireland, road police portals in Bulgaria and Armenia, tax authorities in Greece, and T-Mobile users in the United States.EstoniaUnited Kingdom, Ireland, Spain, France, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (United States, Trinidad & Tobago), and the CaucasusFranceTargeted countries span three regions: Europe (Romania, United Kingdom, Ireland, Spain, France, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (UnitedGeorgiaAlbania, Kosovo, Montenegro), the Americas (United States, Trinidad & Tobago), and the Caucasus (Georgia, Armenia).Germanyprimary provider, with 15 servers across Singapore (43.160.242[.]3, 43.160.221[.]174, 43.160.250[.]19), Germany/Frankfurt (43.157.17[.]77, 43.157.122[.]50, 43.157.64[.]211, 43.165.4[.]234, 43.157.25[.]170,Greecedelivery customers in the UK and Ireland, road police portals in Bulgaria and Armenia, tax authorities in Greece, and T-Mobile users in the United States.Irelandsame infrastructure hitting Romanian taxpayers was also targeting DPD delivery customers in the UK and Ireland, road police portals in Bulgaria and Armenia, tax authorities in Greece, and T-Mobile users in the UnitedKosovoIreland, Spain, France, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (United States, Trinidad & Tobago), and the Caucasus (Georgia, Armenia).Latviaspan three regions: Europe (Romania, United Kingdom, Ireland, Spain, France, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (United States,Lithuania(Romania, United Kingdom, Ireland, Spain, France, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (United States, Trinidad & Tobago), and theMoldova32 backend IP addresses spanning 6 geographic regions, with infrastructure distributed across Tencent Cloud (15 IPs), Alibaba Cloud (3 IPs), Cloudflare CDN (14 IPs), and ALEXHOST in Moldova (2 IPs).MontenegroFrance, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (United States, Trinidad & Tobago), and the Caucasus (Georgia, Armenia).North MacedoniaEurope (Romania, United Kingdom, Ireland, Spain, France, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (United States, Trinidad & Tobago),RomaniaIn May 2026, Romania's official government payment portal Ghișeul.ro posted a public security warning after citizens began reporting fraudulent SMS messages impersonating the platform. That warning pointed to somethingSingaporeTencent is the primary provider, with 15 servers across Singapore (43.160.242[.]3, 43.160.221[.]174, 43.160.250[.]19), Germany/Frankfurt (43.157.17[.]77, 43.157.122[.]50, 43.157.64[.]211, 43.165.4[.]234,SloveniaTargeted countries span three regions: Europe (Romania, United Kingdom, Ireland, Spain, France, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (UnitedSpainTargeted countries span three regions: Europe (Romania, United Kingdom, Ireland, Spain, France, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (UnitedTrinidad & TobagoNorth Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (United States, Trinidad & Tobago), and the Caucasus (Georgia, Armenia).United KingdomTargeted countries span three regions: Europe (Romania, United Kingdom, Ireland, Spain, France, Bulgaria, Slovenia, Latvia, Greece, North Macedonia, Lithuania, Estonia, Albania, Kosovo, Montenegro), the Americas (UnitedUnited Statesroad police portals in Bulgaria and Armenia, tax authorities in Greece, and T-Mobile users in the United States.

Industries

Related Articles