{"id":7506,"date":"2025-04-01T12:00:00","date_gmt":"2025-04-01T17:00:00","guid":{"rendered":"https:\/\/www.threatstop.com\/blog\/toll-scams-are-whats-happen.xin-right-now"},"modified":"2025-04-01T12:00:00","modified_gmt":"2025-04-01T17:00:00","slug":"toll-scams-are-whats-happen-xin-right-now","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/04\/01\/toll-scams-are-whats-happen-xin-right-now\/","title":{"rendered":"Toll Scams Are What&#8217;s Happen.xin Right Now"},"content":{"rendered":"<p>Have you ever received an odd text message on your phone, purporting to be from a toll provider or package delivery service? If you have a U.S. cell phone, chances are you\u2019ve encountered one of these SMiShing attempts\u2014cybercriminals\u2019 latest ploy to trick you into giving up your personal and financial details. SMiShing (a portmanteau of SMS and phishing) relies on victims clicking deceptive links that appear legitimate but actually lead to malicious websites.<\/p>\n<p><!--more--><\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/04\/toll-scams-are-whats-happen-xin-right-now.png?resize=640%2C1385&#038;ssl=1\" width=\"640\" height=\"1385\" loading=\"lazy\" alt=\"IMG_3408\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2025\/04\/toll-scams-are-whats-happen-xin-right-now-1.jpg 642w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2025\/04\/toll-scams-are-whats-happen-xin-right-now.png 1284w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2025\/04\/toll-scams-are-whats-happen-xin-right-now.png 1926w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2025\/04\/toll-scams-are-whats-happen-xin-right-now.png 2568w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2025\/04\/toll-scams-are-whats-happen-xin-right-now.png 3210w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2025\/04\/toll-scams-are-whats-happen-xin-right-now.png 3852w\" sizes=\"auto, (max-width: 1284px) 100vw, 1284px\"><\/p>\n<p>In one recently observed scam, users received text messages about unpaid toll fees with a link that seemed to be connected to a well-known site, such as <span>e-zpass.com<\/span>. Closer inspection, however, revealed the URL actually belonged to something like <span>e-zpass.com-emzwsefybawjadl[.]xin<\/span>, a completely different top level domain (<span>.xin<\/span>) rather than a more legitimate <span>.com<\/span>. The <span>.xin<\/span> TLD was initially introduced as a \u201ctrust-centric\u201d top-level domain, but in practice, many <span>.xin<\/span> domains are being used for criminal activities. ThreatSTOP found more than 7,000 suspicious <span>.xin<\/span> domains designed to mimic toll service providers like E-ZPass and FasTrak, among others, amongst the 43,000+ domains active in the TLD.<\/p>\n<p><span>You may have not heard of .xin until recently. According to <a href=\"https:\/\/icannwiki.org\/.xin\" rel=\"noopener\">ICANN wiki<\/a>:<\/span><\/p>\n<blockquote readability=\"24.559777571826\">\n<p>&#8220;The intention of Elegant Leader Limited (\u201cElegant\u201d) in filing this <a data-lingo-term-id=\"594cb7a6563ab5c889d951982d4f996e\">gTLD<\/a> application is to establish a trusted and reliable namespace in China and in the world. This offers an opportunity for large companies, SMEs, and individuals that are willing to demonstrate themselves as a trusted and reliable entity on the Internet. To fulfill this mission, Elegant expects to align with top-notch registry operator, Afilias Ltd., experienced ICANN accredited registrar, HiChina Zhicheng Technology Ltd., relevant verification and validation agents, and other reputable 3rd-party service providers and neutral associations, to join force and to build a trust-centric .XIN <a data-lingo-term-id=\"594cb7a6563ab5c889d951982d4f996e\">gTLD<\/a>.<\/p>\n<p>Unlike existing <a data-lingo-term-id=\"e800122d43583e63e1740a15d5fa5183\">TLDs<\/a> which may have legacy rules that make some of the registrants data unverified, .XIN aims to verify and validate registrant information at the very beginning of the launch of the <a data-lingo-term-id=\"c509b3bd238b50a1f6f9f3cfd6cc3d2b\">TLD<\/a>, and will do so at an on-going basis. By doing so, .XIN <a data-lingo-term-id=\"594cb7a6563ab5c889d951982d4f996e\">gTLD<\/a> can strengthen the Internet marketplace in China and in the world with elevated level of trust and reliability for both registrants and users.<\/p>\n<\/blockquote>\n<p>But <span>.xin<\/span> is far from the only culprit. These malicious campaigns also exploit TLDs such as <span>.top<\/span>, <span>.vip<\/span>, <span>.win<\/span>, <span>.cc<\/span>, and others, often impersonating known brands and entities like USPS, FedEx, or local transportation authorities.&nbsp;(e.g., <span>fedex.com-gsjb[.]xin<\/span>, <span>usps-verification[.]xin<\/span>, <span>usps.com.tools-packagmur[.]xin<\/span><span> or <\/span><span>mndot-etzwau.xin<\/span>).<\/p>\n<p><strong>How SMiShing Tricks You<\/strong><\/p>\n<ol>\n<li><span><\/span><span><strong>Deceptive Sender<\/strong><\/span>: Attackers pose as official entities, such as toll agencies or delivery services.<\/li>\n<li><span><strong>Fake Links<\/strong><\/span><span>: Cybercriminals craft URLs that look similar to legitimate web addresses. They insert extra segments\u2014<\/span><span>something.com-somethingelse.tld<\/span><span>\u2014making it appear to be a familiar <\/span><span>.com<\/span><span> site when it\u2019s actually a completely different domain.&nbsp;<\/span><span>In fact the best advice &#8211; one that would have saved Troy Hunt of &#8220;HaveIBeenPwned&#8221; <\/span><a href=\"https:\/\/www.troyhunt.com\/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list\/\" rel=\"noopener\">from being PWNed<\/a><span> &#8211; is to never ever visit the link in the SMS or email but go to the website manually and then find the link to where to transact whatever business you are supposed to transact.<\/span><\/li>\n<li><span><strong>Urgency<\/strong><\/span><span>: The message typically uses alarming or urgent language\u2014claims of missed toll fees, missed package deliveries, or even account breaches\u2014to prompt a quick response.<\/span><\/li>\n<li><span><strong>Credential Harvesting<\/strong><\/span><span>: Unwary users who click the link and proceed to enter personal information or credit card data end up handing this valuable information directly to criminals.<\/span><br \/><span><\/span><\/li>\n<\/ol>\n<p><strong>Proactive Ways to Stay Protected<\/strong><\/p>\n<p>The best defense against SMiShing is caution:<\/p>\n<ul>\n<li><span><\/span><span><strong>Examine the Link<\/strong><\/span>: If you see a suspicious domain like <span>.xin<\/span>, <span>.top<\/span>, or <span>.win<\/span> after what appears to be a trusted name, it\u2019s a red flag.<\/li>\n<li><span><\/span><span><strong>Go Direct<\/strong><\/span>: Never click on a link in an unsolicited message. Instead, manually visit the legitimate company\u2019s official site.<\/li>\n<li><span><\/span><span><strong>Enable Protective DNS<\/strong><\/span>: If you accidentally click a malicious link while tired, in a hurry, or simply unaware, having proactive DNS protection can stop you from reaching harmful domains.<\/li>\n<\/ul>\n<hr>\n<p><strong>ThreatSTOP\u2019s Proactive Protections<\/strong><\/p>\n<p>ThreatSTOP\u2019s solutions are designed to help organizations and individuals <span><strong>connect with customers, disconnect from risks<\/strong><\/span>. Our <span><strong>ThreatSTOP Security, Intelligence, and Research team<\/strong><\/span> continuously creates threat protections for command and control, invalid traffic, peer-to-peer communication, data exfiltration, phishing, spam, Distributed Denial of Service (DDoS), and more.<\/p>\n<p><span><span>Protective DNS<\/span><br \/><\/span>\u2022<span> <\/span><a href=\"https:\/\/www.threatstop.com\/dns-defense-cloud\" rel=\"noopener\" target=\"_blank\"><span><strong>Cloud<\/strong><\/span><\/a>: Experience continuous, cloud-based DNS protection without the hassle of deploying or managing your own DNS infrastructure. By redirecting your DNS queries through our intelligence-backed servers, you gain proactive blocking of known malicious domains\u2014like those found in SMiShing attempts\u2014before they can cause any damage.<\/p>\n<p>\u2022&nbsp;<a href=\"https:\/\/www.threatstop.com\/solutions\/threatstop-dns-firewall-overview\" rel=\"noopener\" target=\"_blank\"><strong>On-Prem<\/strong><\/a>: For those running their own DNS infrastructure on-premises, ThreatSTOP\u2019s DNS Defense seamlessly integrates with your existing DNS servers. Our threat intelligence feed ensures your network proactively blocks suspicious domains, helping stop SMiShing attacks in their tracks.<\/p>\n<p>Whether it\u2019s a phishing domain from a lesser-known gTLD or a bulletproof hosting service hidden in plain sight, ThreatSTOP\u2019s integrated platform helps keep your environment safe from evolving threats.<\/p>\n<hr>\n<p><strong>Take the Next Step to Strengthen Your Security<\/strong><\/p>\n<p>For those interested in joining the ThreatSTOP family, or to learn more about our proactive protections for all environments, we invite you to visit our\u202f<a href=\"https:\/\/www.threatstop.com\/threatstop-platform\" rel=\"noopener\" target=\"_blank\">product page<\/a>. Discover how our solutions can make a significant difference in your digital security landscape. We have\u202fpricing\u202ffor all sizes of customers! Get started with a Demo today!<\/p>\n<p><strong>Connect with Customers, Disconnect from Risks<\/strong><\/p>\n<table>\n<thead>\n<tr>\n<th>\n<p><strong>Tactic<\/strong><\/p>\n<\/th>\n<th>\n<p><strong>Technique<\/strong><\/p>\n<\/th>\n<th>\n<p><strong>ID<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody readability=\"2.3609467455621\">\n<tr readability=\"1.4571428571429\">\n<td>\n<p><strong>Initial Access (TA0001)<\/strong><\/p>\n<\/td>\n<td readability=\"0\">\n<p><a href=\"https:\/\/attack.mitre.org\/techniques\/T1566\/003\/\">SMiShing (Spearphishing via Service)<\/a><\/p>\n<\/td>\n<td>\n<p><strong>T1566.003<\/strong><\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td readability=\"5\">\n<p><strong>Credential Access (TA0006)<\/strong><\/p>\n<\/td>\n<td readability=\"5\">\n<p>Exploit User Submission (harvesting credentials via fake forms)<\/p>\n<\/td>\n<td>\n<p><i>Varies<\/i>*<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><i>*While there isn\u2019t a single specific MITRE technique ID that covers \u201cuser submission of credentials via fake web forms,\u201d this tactic often involves social engineering under <\/i><a href=\"https:\/\/attack.mitre.org\/techniques\/T1566\/\"><i>Phishing (T1566)<\/i><\/a><i> and potentially can lead to other credential harvesting methods once the user information is obtained.<\/i><i><\/i><\/p>\n<p>By understanding these techniques and employing proactive protections, organizations and individuals can better defend themselves against SMiShing threats and their evolving tactics.<\/p>\n<p><a href=\"https:\/\/www.threatstop.com\/blog\/toll-scams-are-whats-happen.xin-right-now\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Have you ever received an odd text message on your<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[30,62,215,216,61],"tags":[68],"class_list":["post-7506","post","type-post","status-publish","format-standard","hentry","category-dns","category-dns-security","category-passive-dns","category-pdns","category-protective-dns","tag-protective-dns"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Threat Stop","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/threatstop\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns\/\" rel=\"category tag\">DNS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns-security\/\" rel=\"category tag\">DNS Security<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/passive-dns\/\" rel=\"category tag\">Passive DNS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/pdns\/\" rel=\"category tag\">PDNS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/protective-dns\/\" rel=\"category tag\">Protective DNS<\/a>","tag_info":"Protective DNS","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=7506"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7506\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=7506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=7506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=7506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}