Over 10,000 domains have been linked to fake toll and package delivery services. Overall, the China-linked Smishing Triad has exploited 194,000 domains in its global phishing campaign.
The cybersecurity firm attributes the operation to a Chinese-speaking threat actor active since at least 2023. Alongside SMS-based phishing, the group has also targeted iPhone users through iMessage, with recent attacks mimicking communications from India Post.
Earlier this year, the Smishing Triad reportedly boasted on its Telegram channel about a new phishing toolkit called “Lighthouse”, capable of targeting major Western financial institutions and banks across Australia and the broader Asia-Pacific region.
Palo Alto Networks initially detected the campaign in March 2024, linking more than 10,000 domains to fraudulent toll and parcel delivery sites.
By April, that number had grown to 91,500 root domains, and further analysis has now uncovered a staggering 194,000 malicious domains used since January 1, 2024.
The attacks impersonate a wide range of entities — from logistics and healthcare providers to banks, law enforcement, and social media companies — in efforts to harvest personal and financial information.
While U.S. users have been the primary targets, the campaign’s reach is global, with victims reported in Australia, the UK, France, Germany, Canada, India, and more than a dozen other countries.
“The campaign is highly decentralised, lacking a single point of control, and uses a large number of domains and a diverse set of hosting infrastructure,” said Palo Alto Networks
“This is advantageous for the attackers as churning through thousands of domains weekly makes detection more difficult,” it said.
Palo Alto Networks reports that the Smishing Triad’s ongoing phishing campaign continues to evolve rapidly, with an extensive network of domains supporting its large-scale smishing operation.
The campaign uses highly personalised text messages that create a sense of urgency, tricking victims into visiting fake websites and revealing sensitive data such as Social Security numbers and national ID details.
Investigators believe the operation is backed by a phishing-as-a-service (PhaaS) model, involving a coordinated supply chain of cybercriminals — including data brokers, domain sellers, hosting providers, phishing kit developers, and SMS spammers.
Dedicated support teams reportedly validate phone numbers and monitor for blocked or inactive domains to keep the campaign active.
The scale and turnover of infrastructure are immense: 82.6% of the malicious domains were active for less than two weeks, with nearly 30% lasting only two days.
Fewer than 6% remained operational three months after registration, underscoring the threat group’s strategy of using disposable infrastructure to evade detection.
Analysis shows that around 90,000 domains impersonated toll services, while over 28,000 mimicked the U.S. Postal Service (USPS).
Other fake domains targeted a range of entities including consumer electronics brands, financial institutions, government departments such as the IRS and state vehicle agencies, police forces, ridesharing platforms, hospitality services, and even online gaming marketplaces.
“We advise people to exercise vigilance and caution. People should treat any unsolicited messages from unknown senders with suspicion,”
“We recommend that people verify any request that demands urgent action using the official service provider’s website or application,” Palo Alto Networks warned.

