Cybercriminals have launched a sophisticated malware campaign that leverages techniques to mimic well-known brands to distribute malware. The attacks typically begin with phishing SMS messages (a technique known as smishing).

This emerging threat shows an evolution in social engineering tactics, where attackers strategically create URLs containing trusted brand names to bypass user suspicions and security filters.
Abuse of known brands: How attackers operate?
The attack methodology focuses on manipulating URL structures to create a false sense of legitimacy. Malicious users incorporate well-known brand names before the “@” symbol into malicious URLs. The actual malicious domain follows. This technique exploits user psychology, as recipients often focus on well-known brand names rather than carefully examining the overall URL structure.
See also: Hundreds of free VPN apps leak user data
Unit 42 researchers have identified that this wave of attacks extends beyond simple URL manipulation, incorporating deceptively named group messaging campaigns to enhance credibility.
Additionally, attackers have shown particular interest in using .xin domain extensions, which provide an additional layer of concealment while maintaining an appearance of legitimacy.
Distribution via phishing SMS
The campaigns typically begin via SMS messages that appear to come from legitimate organizations, directing recipients to click on malicious links for account verification, delivery notifications, or security alerts. Upon interaction, these URLs redirect users to credential collection pages or trigger automatic malware downloads targeting mobile and desktop platforms.

The sophisticated nature of these attacks lies in the multi-stage process infection and domain preparation strategies. Attackers pre-register domains months in advance, which allows them to establish domain reputation scores that evade automated security checks. The malicious infrastructure uses rotating subdomains and URL shortening services to complicate tracking efforts.
The malicious payload delivery mechanism uses progressive profiling, where initial clicks collect device fingerprinting data before deploying platform-specific malware variants. This approach maximizes infection success rates while minimizing detection by security solutions that rely on static URL analysis.
See also: Hackers use WhatsApp to distribute SORVEPOTEL malware
Advanced threats
The attacks described are a transformed form of social engineering: the perpetrators no longer rely only on the deception of the message, but on the very shape of the links. Studying their dynamics, we see that their success is based on three axes: psychological lure, technical sophistication and timing. Psychological lure has to do with the trust in well-known brands and the speed of reaction of the victims. Technical sophistication includes domain pre-registrations, rotating sub-domains and a combination of shortcut services that disguise the origin. Timing — with campaigns that spread the activity over weeks or months — unbalances detection systems.

Countering such attacks requires a multi-layered defense: educating users on effective URL checking, enforcing DMARC/SPF policies, and dynamic endpoint controls that block suspicious redirects. In addition, security providers must improve telemetry collection and share real-time indicators of compromise. Technologies such as sandboxing on mobile platforms and network-level behavioral analysis reduce the damage when the user interacts.
See also: Confucius targets Windows systems with the AnonDoor backdoor
Ultimately, prevention requires constant vigilance: adversary intelligence is increasing, so defense practices must evolve more quickly. Additionally, organizations should adopt least privilege policies and limit the distribution of sensitive links via SMS. Rapid incident reporting to CERTs and the use of automated domain suspension technologies can reduce the scale of attacks. Training and technical measures must be effectively combined.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
