{"id":6332,"date":"2024-11-19T13:00:00","date_gmt":"2024-11-19T19:00:00","guid":{"rendered":"https:\/\/www.threatstop.com\/blog\/we-like-getting-smished"},"modified":"2024-11-19T13:00:00","modified_gmt":"2024-11-19T19:00:00","slug":"smishmas-cheer-turning-threats-into-protections","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/11\/19\/smishmas-cheer-turning-threats-into-protections\/","title":{"rendered":"Smishmas Cheer: Turning Threats into Protections"},"content":{"rendered":"<p>Phishing email and &#8220;Smishing&#8221; texts have become a daily annoyance for anyone with a smartphone or computer &#8212; even our own team at ThreatSTOP isn&#8217;t immune. &nbsp;However, instead of just dodging these attempts, we leverage them to strengthen our proactive protections for customers. Recently, we encountered a smishing text directing recipients to a malicious domain masquerading as the USPS (United States Postal Service). &nbsp;After investigating, we expanded our protections to cover not just one malicious domain but an entire network of fraudulent activity.&nbsp;<\/p>\n<p><!--more--><\/p>\n<p>When we receive a phish or smish, the first step is adding the domains they ask us to visit to our phishing targets. This ensures no one accidentally clicks those links again. But in some cases, like this USPS-themed phishing campaign, there\u2019s more to uncover:<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/smishmas-cheer-turning-threats-into-protections.png?resize=640%2C968&#038;ssl=1\" loading=\"lazy\" width=\"640\" height=\"968\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/smishmas-cheer-turning-threats-into-protections-1.jpg 621w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/smishmas-cheer-turning-threats-into-protections.png 1242w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/smishmas-cheer-turning-threats-into-protections.png 1863w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/smishmas-cheer-turning-threats-into-protections.png 2484w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/smishmas-cheer-turning-threats-into-protections.png 3105w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/smishmas-cheer-turning-threats-into-protections.png 3726w\" sizes=\"auto, (max-width: 1242px) 100vw, 1242px\"><\/p>\n<p>Using investigative tools like <strong>urlscan.io<\/strong>, we found that the phishing domain redirected users to a fake USPS tracking page. A deeper search of related domains revealed a pattern: hundreds of <strong>infotrackXXX.top<\/strong> URLs hosted on Cloudflare infrastructure, all mimicking USPS tracking notifications.<\/p>\n<p>&nbsp;&#8211; <a href=\"https:\/\/urlscan.io\/result\/7cfe664d-60dc-4018-a83f-4c11e49ed22f\/\">https:\/\/urlscan.io\/result\/7cfe664d-60dc-4018-a83f-4c11e49ed22f\/<\/a><\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/smishmas-cheer-turning-threats-into-protections-1.png?resize=640%2C480&#038;ssl=1\" loading=\"lazy\" width=\"640\" height=\"480\"><\/p>\n<p>Thanks to ICANN\u2019s Centralized Zone Data Service <span>(<a href=\"https:\/\/czds.icann.org\/home\" rel=\"noopener\">CZDS<\/a>)<\/span>, we discovered over 1,000 domains matching this pattern, with more registered every day. While some are occasionally inactive, our analysis confirmed that every active domain was a fake USPS site.<\/p>\n<p>Building Proactive Protections<\/p>\n<p>ThreatSTOP quickly blocked all identified domains across our products, providing comprehensive protection for millions of customers worldwide. Whether it\u2019s businesses safeguarding their networks or individuals relying on our DNS solutions, our platform ensures threats like these never reach their targets:<\/p>\n<ul>\n<li><strong>DNS Defense Cloud<\/strong> users were shielded at the DNS layer through our cloud-based DNS servers.<\/li>\n<li><strong>DNS Defense<\/strong> customers, who manage their own DNS servers, gained the same proactive protections through seamless updates to their systems.<\/li>\n<li><strong>IP Defense<\/strong> extended protections to firewalls, routers, and other IP-based systems, ensuring these threats were neutralized at every level.<\/li>\n<\/ul>\n<p>The beauty of our platform is how quickly we can respond. As new domains are registered in this campaign, our systems are updated automatically to block them, providing continuous protection against this evolving threat.<\/p>\n<p><strong>Holiday Readiness: Proactive, Not Reactive<\/strong><\/p>\n<p>This type of phishing campaign is especially timely as the holiday season approaches. With millions of Americans relying on USPS tracking notifications for gifts and packages, cybercriminals are exploiting this trend. But with ThreatSTOP, you can confidently move through this season knowing your systems are protected against these malicious campaigns.<\/p>\n<p>At ThreatSTOP, we don\u2019t just defend against threats\u2014we turn them into opportunities to strengthen our protections. So, yes, we may even enjoy getting \u201csmished\u201d this time of year because every attempt against us becomes a proactive safeguard for you.<\/p>\n<p><strong>Connect with Customers, Disconnect from Risks<\/strong><\/p>\n<p>For those interested in joining the ThreatSTOP family, or to learn more about our proactive protections for all environments, we invite you to visit our <a href=\"https:\/\/www.threatstop.com\/threatstop-platform\" rel=\"noopener\" target=\"_blank\">product page<\/a>. Discover how our solutions can make a significant difference in your digital security landscape. We have pricing for all sizes of customers! Get started with a demo today!<\/p>\n<p><a href=\"https:\/\/www.threatstop.com\/blog\/we-like-getting-smished\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing email and &#8220;Smishing&#8221; texts have become a daily annoyance<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[30,62,215,216,61,1069],"tags":[1071],"class_list":["post-6332","post","type-post","status-publish","format-standard","hentry","category-dns","category-dns-security","category-passive-dns","category-pdns","category-protective-dns","category-smishing","tag-smishing"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Threat Stop","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/threatstop\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns\/\" rel=\"category tag\">DNS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns-security\/\" rel=\"category tag\">DNS Security<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/passive-dns\/\" rel=\"category tag\">Passive DNS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/pdns\/\" rel=\"category tag\">PDNS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/protective-dns\/\" rel=\"category tag\">Protective DNS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/smishing\/\" rel=\"category tag\">Smishing<\/a>","tag_info":"Smishing","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6332","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6332"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6332\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6332"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6332"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}