HomeSecurityCybercriminals imitate well-known brands to scam users

Cybercriminals imitate well-known brands to scam users

Cybercriminals have launched a sophisticated malware campaign that leverages techniques to mimic well-known brands to distribute malware. The attacks typically begin with phishing SMS messages (a technique known as smishing).

 popular brands Cybercriminals

This emerging threat shows an evolution in social engineering tactics, where attackers strategically create URLs containing trusted brand names to bypass user suspicions and security filters.

Abuse of known brands: How attackers operate?

The attack methodology focuses on manipulating URL structures to create a false sense of legitimacy. Malicious users incorporate well-known brand names before the “@” symbol into malicious URLs. The actual malicious domain follows. This technique exploits user psychology, as recipients often focus on well-known brand names rather than carefully examining the overall URL structure.

See also: Hundreds of free VPN apps leak user data

Unit 42 researchers have identified that this wave of attacks extends beyond simple URL manipulation, incorporating deceptively named group messaging campaigns to enhance credibility.

Additionally, attackers have shown particular interest in using .xin domain extensions, which provide an additional layer of concealment while maintaining an appearance of legitimacy.

Distribution via phishing SMS

The campaigns typically begin via SMS messages that appear to come from legitimate organizations, directing recipients to click on malicious links for account verification, delivery notifications, or security alerts. Upon interaction, these URLs redirect users to credential collection pages or trigger automatic malware downloads targeting mobile and desktop platforms.

Cybercriminals imitate well-known brands to scam users

The sophisticated nature of these attacks lies in the multi-stage process infection and domain preparation strategies. Attackers pre-register domains months in advance, which allows them to establish domain reputation scores that evade automated security checks. The malicious infrastructure uses rotating subdomains and URL shortening services to complicate tracking efforts.

The malicious payload delivery mechanism uses progressive profiling, where initial clicks collect device fingerprinting data before deploying platform-specific malware variants. This approach maximizes infection success rates while minimizing detection by security solutions that rely on static URL analysis.

See also: Hackers use WhatsApp to distribute SORVEPOTEL malware

Advanced threats

The attacks described are a transformed form of social engineering: the perpetrators no longer rely only on the deception of the message, but on the very shape of the links. Studying their dynamics, we see that their success is based on three axes: psychological lure, technical sophistication and timing. Psychological lure has to do with the trust in well-known brands and the speed of reaction of the victims. Technical sophistication includes domain pre-registrations, rotating sub-domains and a combination of shortcut services that disguise the origin. Timing — with campaigns that spread the activity over weeks or months — unbalances detection systems.

Cybercriminals imitate well-known brands to scam users

Countering such attacks requires a multi-layered defense: educating users on effective URL checking, enforcing DMARC/SPF policies, and dynamic endpoint controls that block suspicious redirects. In addition, security providers must improve telemetry collection and share real-time indicators of compromise. Technologies such as sandboxing on mobile platforms and network-level behavioral analysis reduce the damage when the user interacts.

See also: Confucius targets Windows systems with the AnonDoor backdoor

Ultimately, prevention requires constant vigilance: adversary intelligence is increasing, so defense practices must evolve more quickly. Additionally, organizations should adopt least privilege policies and limit the distribution of sensitive links via SMS. Rapid incident reporting to CERTs and the use of automated domain suspension technologies can reduce the scale of attacks. Training and technical measures must be effectively combined.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS