On SMS Phishing Tactics and Infrastructure
Aleksandr Nahapetyan, Sathvik Prasad, Kevin Childs, Adam Oest, Yeganeh Ladwig, Alexandros Kapravelos
IEEE Symposium on Security and Privacy 2024 · Day 1 · Continental Ballroom 4
Overview
SMS phishing, commonly known as smishing, represents a pervasive and evolving threat in the landscape of social engineering attacks. This presentation, delivered by Aleksandr Nahapetyan from NC State University, details a collaborative research effort with PayPal, published at IEEE S&P 2024, that sheds light on the tactics and underlying infrastructure leveraged by SMS phishers. The talk addresses the critical need for a deeper understanding of smishing operations, which have consistently increased over the past four years, as reported by the Anti-Phishing Working Group (APWG).

Key moments
- 0:00 Introduction to SMS phishing & study approach
- 0:50 Collecting SMS phishing data from public gateways
- 2:00 Example of a Bitcoin wallet phishing campaign
- 2:40 Data pipeline: URL extraction, clustering into operations
- 4:00 Findings on hostnames, SSL certificates, URL shorteners
- 5:50 Attackers use SMS gateways to test delivery routes
- 6:50 Discovering bulk SMS services for malicious traffic
- 7:30 Summary of SMS phishing operations & ecosystem
On SMS Phishing Tactics and Infrastructure
Speakers: Aleksandr Nahapetyan; Sathvik Prasad; Kevin Childs; Adam Oest; Yeganeh Ladwig; Alexandros Kapravelos
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=HqRstw_1Qk
Overview
SMS phishing, commonly known as smishing, represents a pervasive and evolving threat in the landscape of social engineering attacks. This presentation, delivered by Aleksandr Nahapetyan from NC State University, details a collaborative research effort with PayPal, published at IEEE S&P 2024, that sheds light on the tactics and underlying infrastructure leveraged by SMS phishers. The talk addresses the critical need for a deeper understanding of smishing operations, which have consistently increased over the past four years, as reported by the Anti-Phishing Working Group (APWG).
The research is particularly significant because while SMS phishing is a Telco abuse phenomenon, it heavily relies on web resources to lure victims into divulging sensitive information. This dual nature allows researchers to employ web abuse techniques—such as analyzing registrars, hostnames, and SSL certificate information—to study and quantify the activity. By leveraging publicly available SMS gateways as a novel data source, the team was able to collect an unprecedented volume of smishing messages, cluster them into campaigns and operations, and uncover crucial insights into attacker methodologies, infrastructure choices, and the lifecycle of these malicious activities. The findings offer valuable intelligence for both telecommunication providers and cybersecurity defenders.
Background
▶ Watch: Introduction to SMS phishing & study approach (0:00)
Phishing, at its core, is a social engineering attack where malicious actors impersonate trustworthy entities to trick individuals into revealing sensitive data or granting unauthorized access. SMS phishing, or smishing, distinguishes itself through its delivery vector: text messages. Prior research has demonstrated its high effectiveness in controlled simulations, partly due to the inherent trust often placed in messages received on personal mobile devices and the perceived legitimacy of messages that appear to come from known organizations. Unlike email phishing, which is primarily a web-based attack, smishing bridges the gap between telecommunications infrastructure and web-based exploits.
The challenge in studying smishing has traditionally been data collection, as SMS traffic is largely private. To overcome this, the research team turned to public SMS gateways. These websites, often designed for testing or receiving messages without a personal phone, display incoming SMS messages to a specific number. Some gateways provide real-time updates, while others offer historic records dating back to their acquisition of the number. The researchers systematically crawled a total of 11 such public SMS gateways, amassing an extensive dataset of over 200 million messages. From this colossal dataset, 60,000 messages were identified as phishing, which were subsequently isolated into 35,000 distinct campaigns. These campaigns were further clustered into more than 600 unique operations, providing a granular view of attacker activity. The revenue model for these gateways, often relying on advertisements, inadvertently creates a public window into malicious SMS traffic.
The data collection pipeline was meticulously designed: first, the gateways were crawled to extract the "to" and "from" phone numbers, the message body, and the timestamp. Next, URLs embedded within the SMS messages were extracted using regular expressions. These URLs were then submitted to VirusTotal for evaluation. To minimize false positives, a strict threshold was applied: an SMS message was only marked as phishing if a sufficient number of VirusTotal engines labeled its associated URL as malicious. Once confirmed as phishing, messages were clustered into campaigns. This clustering was not based on edit distance but on exact textual similarity after replacing dynamic elements like URLs, phone numbers, one-time codes (OTCs), and email addresses with placeholders. Finally, these campaigns were used to construct a bipartite graph where nodes represented campaigns and the URLs they utilized. Connected components within this graph were then defined as operations, providing a holistic view of attacker infrastructure reuse and tactical coordination across multiple campaigns.
Key Findings
▶ Watch: Example of a Bitcoin wallet phishing campaign (2:00)
The research yielded several critical insights into the operational characteristics and infrastructure choices of SMS phishing campaigns:
- URL Redirection: A significant majority of URLs embedded in initial phishing messages were found to redirect victims to a different hostname entirely. This tactic helps obfuscate the true malicious destination and evade initial detection.
- SSL Certificate Pre-issuance: For many observed hostnames, the associated SSL certificates were issued weeks before the researchers first encountered the corresponding URL on the SMS gateways. This suggests a degree of pre-planning and infrastructure setup by attackers, rather than rapid, on-the-fly deployments.
- Cloud Service Provider Preference: The most common cloud service providers hosting these malicious websites were Cloudflare, AWS, and Google. This highlights attackers' reliance on major, reputable cloud platforms, likely for their reliability, scalability, and perceived legitimacy.
- Absence of Seasonality: Unlike some other forms of Telco fraud, SMS phishing activities did not exhibit any discernible seasonality in traffic patterns, indicating a consistent, year-round threat.
- Prevalence of URL Shorteners: The top five second-level domains (SLDs) observed in the dataset were all URL shorteners. Interestingly, only two of these were public services; the remaining three appeared to be private shorteners, suggesting they are either custom-built by malicious actors or offered as specialized services exclusively for illicit activities.
- Shorter Hostnames: Compared to generic phishing URLs identified in prior work, SMS phishing hostnames tended to be significantly shorter, with an observed upper bound of approximately 40 characters. The average character length for campaign messages was about 90 characters, leaving limited space for the URL (including schema, hostname, and path), which incentivizes the use of shorter hostnames and URL shorteners.
- SMS Gateways as Testing Grounds: A particularly novel finding was the use of public SMS gateways by malicious actors to test their traffic delivery routes. The presence of 45 operations (comprising 161 campaigns) with a textual pattern of "Route: [number]" within the messages, coupled with 16 hostnames having SSL certificates issued just 12 hours after their first appearance on these gateways, strongly indicates a testing phase before wider deployment to actual victims.
- Campaign Similarity within Operations: Multi-campaign operations, defined by shared URLs, exhibited high textual similarity when compared using edit distance, reinforcing the idea that these are coordinated efforts by the same threat actor or group.
- Top Targeted Entities: The most frequently mentioned entities in phishing operations were Apple, Common Bank, d CH, and the Australian government. However, a significant 87% of operations did not mention any detectable named entity, suggesting a broad, generic approach for many campaigns.
- Ecosystem of Bulk SMS Services: The research uncovered an active ecosystem of individuals advertising bulk SMS services on platforms like LinkedIn. While these advertisements on LinkedIn avoid explicit mention of malicious use, corresponding discussions in Telegram groups (e.g., "General Fishing") explicitly link back to these LinkedIn posts, revealing a market for delivering spam and malicious content.
Overall, these findings paint a comprehensive picture of SMS phishing, from its technical underpinnings to its operational tactics and the broader ecosystem that supports it.
Technical Deep Dive
▶ Watch: Findings on hostnames, SSL certificates, URL shorteners (4:00)
The technical methodology employed in this research provides a robust framework for understanding SMS phishing infrastructure and tactics. The core innovation lies in leveraging public SMS gateways as a novel data source, transforming a traditionally opaque threat into an observable phenomenon.
The data collection pipeline commenced with the systematic crawling of 11 public SMS gateways. For each incoming message, the system recorded the to and from phone numbers, the full message body, and the timestamp. This raw data, totaling over 200 million messages, formed the foundation for subsequent analysis. A critical step was URL extraction, performed using regular expressions to identify all embedded links within the message bodies. These extracted URLs were then submitted to VirusTotal, a widely recognized aggregation of antivirus engines and URL scanners, for initial classification. To ensure high fidelity and minimize false positives, a pragmatic threshold was set: an SMS message was only classified as phishing if a sufficient number of VirusTotal engines flagged its associated URL as malicious. This conservative approach ensured that the identified 60,000 phishing messages were genuinely malicious.
The subsequent clustering methodology was key to organizing the vast amount of raw phishing data into actionable intelligence. Instead of relying on fuzzy string matching like edit distance, the researchers adopted a precise approach for defining campaigns. Messages were grouped into the same campaign if they were textually identical after replacing dynamic elements such as URLs, phone numbers, one-time codes (OTCs), and email addresses with standardized placeholders. This method effectively normalized variations in victim-specific or transient data, revealing the underlying template used by phishers. Building on campaigns, the concept of an operation was introduced. This involved constructing a bipartite graph where one set of nodes represented the identified campaigns and the other set represented the URLs used within those campaigns. An edge connected a campaign node to a URL node if that URL was present in the campaign. Connected components within this bipartite graph were then defined as operations. This graph-based approach is powerful because it reveals how multiple campaigns might be linked through shared infrastructure (URLs), even if their message content varies slightly, providing a holistic view of a threat actor's coordinated activities. For instance, a single operation could encompass multiple campaigns utilizing one or more shared URLs, demonstrating infrastructure reuse.
Further technical analysis delved into the characteristics of the observed infrastructure. The study examined SSL certificate information for the hostnames associated with phishing URLs. By analyzing the issuance dates of these certificates, the researchers could estimate the time of deployment for the underlying domains. This revealed that many certificates were issued weeks before the URLs appeared on the gateways, indicating a proactive setup phase by attackers. The identification of Cloudflare, AWS, and Google as dominant cloud service providers was achieved by analyzing DNS records and IP address ranges associated with the hostnames. The team also conducted an in-depth analysis of URL shorteners, distinguishing between publicly accessible services and those that appeared to be private, custom-built tools. This involved attempting to register and use the identified shorteners to determine their public availability.
A particularly insightful technical finding concerned the use of SMS gateways for delivery route testing. The researchers identified specific textual patterns, such as "Route: [number]," within phishing messages. Correlating these patterns with SSL certificate issuance timings (e.g., certificates issued just 12 hours after the first message arrival) provided strong evidence that attackers were actively testing their delivery infrastructure on these public gateways before launching full-scale attacks. This "pre-attack" observable behavior is a significant discovery for proactive threat intelligence. The analysis of campaign similarity within multi-campaign operations, using edit distance on the placeholder-normalized messages, further confirmed the coordinated nature of these operations. Finally, to understand the broader enablers of SMS phishing, the researchers performed a large-scale crawl of LinkedIn for advertisements of bulk SMS services, identifying over 40,000 posts. Cross-referencing these with discussions in Telegram groups like "General Fishing" revealed the explicit intent to use these services for malicious purposes, thus mapping out a significant component of the attacker ecosystem. This multi-faceted technical approach, combining data collection, sophisticated clustering, infrastructure analysis, and cross-platform investigation, provides an unprecedented level of detail into the inner workings of SMS phishing.
Demo / Proof of Concept
▶ Watch: Attackers use SMS gateways to test delivery routes (5:50)
While the presentation did not feature a live, interactive demonstration of an exploit, it effectively showcased the research methodology and validated its findings through compelling examples and evidence derived from the collected data.
One primary "proof of concept" presented was the illustration of how known, documented phishing campaigns were successfully captured by the public SMS gateways used in the study. The speaker referenced a specific phishing campaign documented by Bleeping Computer, which involved victims receiving a text message with a URL to what appeared to be a Bitcoin wallet, complete with a username, password, and a fabricated Bitcoin balance. Upon logging in, the malicious website would prompt users for credit or debit card information to "withdraw" their supposed Bitcoin. The research team demonstrated that messages from this exact campaign were indeed recorded by their crawled gateways, with one specific number receiving the same message twice within a two-week span. This served as concrete validation that the public SMS gateways were effectively capturing real-world, active phishing traffic, thereby proving their utility as a data source for studying smishing.
Another key "proof of concept" involved demonstrating the existence and interconnectedness of the bulk SMS service ecosystem that facilitates phishing. The researchers detailed their process of crawling LinkedIn, identifying over 40,000 advertisements for bulk SMS services. To illustrate the malicious intent behind some of these services, the presentation included a screenshot from a Telegram group named "General Fishing." In this screenshot, an individual explicitly linked back to one of the LinkedIn advertisements, openly discussing the use of such services for phishing and spam. This visual evidence clearly connected the seemingly legitimate bulk SMS advertising on professional platforms like LinkedIn with the darker, malicious intent discussed in private, illicit forums on Telegram. This served as a powerful illustration of how attackers procure their delivery mechanisms and highlighted a significant avenue for disrupting the smishing supply chain. These examples, though not a traditional live demo, effectively validated the research's data sources and the inferences drawn about attacker tactics and infrastructure.
Defensive Implications
▶ Watch: Summary of SMS phishing operations & ecosystem (7:30)
The findings from this research provide actionable intelligence for a broad spectrum of defenders, from telecommunications carriers to cybersecurity professionals and end-users. Understanding the tactics and infrastructure of SMS phishing is crucial for developing effective countermeasures.
Firstly, for telecommunication carriers and A2P (Application-to-Person) messaging providers, the research highlights a critical vulnerability in the bulk messaging ecosystem. Carriers currently tend to treat SMS phishing primarily as an access control issue to bulk messaging interfaces. However, the discovery of a thriving ecosystem of individuals advertising bulk SMS services, often with explicit malicious intent on underground forums, suggests a deeper systemic problem. Carriers need to re-evaluate their vetting processes for A2P providers and proactively monitor for the abuse of their infrastructure by these third-party services. Collaborating with law enforcement and cybersecurity researchers to identify and disrupt these illicit bulk SMS providers should be a priority.
Secondly, for security researchers and threat intelligence analysts, the study introduces public SMS gateways as an invaluable, underutilized resource for proactive threat detection. By continuously crawling and analyzing messages on these gateways, researchers can identify emerging phishing campaigns and attacker infrastructure before they are widely deployed to actual victims. The observation that attackers use these gateways to "test delivery routes" (evidenced by patterns like "Route: [number]" and rapid SSL certificate issuance) offers a unique window into the pre-attack phase. Monitoring for these specific indicators can enable earlier detection and blacklisting of malicious URLs and phone numbers, significantly reducing the window of opportunity for attackers.
Thirdly, the insights into attacker infrastructure choices are vital. Defenders should focus on:
- Monitoring SSL Certificate Issuance: The finding that certificates are often issued weeks in advance suggests that monitoring certificate transparency logs for newly issued certificates targeting suspicious hostnames or those linked to previously identified phishing campaigns could provide early warnings.
- Cloud Provider Abuse: The reliance on Cloudflare, AWS, and Google indicates that these major cloud providers need to enhance their abuse detection and takedown mechanisms. Defenders should also focus on identifying and reporting malicious content hosted on these platforms.
- URL Shortener Vigilance: The prevalence of both public and private URL shorteners in SMS phishing necessitates enhanced detection capabilities for shortened URLs, especially those from unidentifiable or custom services. URL expansion services can be integrated into security solutions to reveal the true destination before a user clicks.
Finally, for end-users and organizations, increased awareness is paramount. The top targeted entities (Apple, Common Bank, Australian government) indicate that users should be particularly cautious of SMS messages purporting to be from these organizations. The finding that many operations do not mention a named entity also underscores the need for general skepticism towards unsolicited messages containing URLs or requests for sensitive information. Education on how to recognize the characteristics of SMS phishing, such as unexpected messages, requests for urgent action, or suspicious links, remains a fundamental defensive layer. Organizations should implement robust multi-factor authentication (MFA) and educate employees on reporting suspicious SMS messages to prevent account compromise.
Key Takeaways
- Public SMS Gateways are a Potent Research Tool: Public SMS gateways offer an invaluable and underutilized resource for collecting vast amounts of real-world SMS phishing data, enabling in-depth study of attacker tactics and infrastructure.
- Phishers Test Delivery Infrastructure: Malicious actors actively use public SMS gateways to test their SMS delivery routes and campaign infrastructure, providing a unique opportunity for early detection and proactive threat intelligence.
- SMS Phishing Operations are Coordinated and Dynamic: Operations are often short-lived, typically employ one to two URLs, and demonstrate significant textual similarity across campaigns, indicating coordinated efforts by threat actors.
- Web Abuse Techniques Apply to Telco Fraud: Analyzing web resources like hostnames, SSL certificates, and cloud providers associated with phishing URLs is highly effective in understanding and combating Telco abuse phenomena like SMS phishing.
- An Ecosystem Facilitates Bulk Messaging Abuse: A robust, albeit illicit, ecosystem of individuals advertising bulk SMS services on platforms like LinkedIn and coordinating on Telegram groups actively supports and enables the large-scale deployment of SMS phishing campaigns.
- Shorter Hostnames and URL Shorteners are Common: SMS phishing hostnames tend to be shorter (under 40 characters), and URL shorteners (both public and private) are heavily utilized to condense links within the character-limited SMS format.
About the Speaker(s)
The lead presenter for this research was Aleksandr Nahapetyan, representing NC State University. This work was a significant collaborative effort, developed in conjunction with his colleagues Sathvik Prasad, Kevin Childs, Adam Oest, Yeganeh Ladwig, and Alexandros Kapravelos. The project was conducted in partnership with PayPal, highlighting a valuable collaboration between academia and industry to address real-world security challenges. The research was published at the prestigious IEEE S&P 2024 conference, underscoring its impact and the rigorous peer review it underwent within the cybersecurity community.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This research introduces a highly novel methodology for understanding SMS phishing by leveraging public SMS gateways as a real-time data source. The detailed infrastructure analysis and discovery of attacker testing behaviors provide unprecedented visibility into smishing operations, offering critical, actionable intelligence for threat defenders and telcos.
Heather Calloway (CISO) — MUST SEE
This research presents a novel and highly effective methodology for understanding SMS phishing operations by leveraging public SMS gateways. Its key findings, particularly the discovery of attacker testing grounds and the mapping of the illicit bulk SMS service ecosystem, provide critical, actionable intelligence for telecommunications carriers, cybersecurity leaders, and threat intelligence teams, fundamentally shifting how we can proactively address this pervasive threat.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024