We have already mentioned enough and now we know what 'phishing' is, but now we will also learn about 'Smishing'.... Hackers use phishing messages and hack websites to steal users' credentials, but Chinese banking users have been faced with a new type of threat in the form of phishing texts.

These text messages are allegedly sent from the official number of China's largest bank. The GSM standard is certainly not the most secure network and that's why mobile phone and network authentication is going in one direction.
The network authenticates the client, but the client never controls the network, according to McAfee.
Additionally, an attacker can easily send mass text messages from a fake base station to a large number of mobile device users by exploiting this feature.
Did you know: Most banks in the UK have weak encryption!
You can see the screen capture from a Wechat app user who received an SMS text message from the fake base station.

The message states that the mobile bank account is unavailable and the recipient of the message is redirected to fake websites.
These fake websites appear to be the bank's real web interface and ask the user to enter their account number, mobile phone number, and bank account login password. By providing this information, the user is supposedly 'helped' to register for mobile phone banking features.
In the image below we can see the differences between the fake (left) and the real (right) interface of the bank.

Apparently, when the user enters this information, the attacker steals their money from their account.
The problem is that this new SMS phish campaign uses the official bank number and causes complete confusion by appearing as authentic.
