Skip to content

Tired of Unpaid Toll Texts? Blame the 'Smishing Triad'

Darkreading Nate Nelson, Contributing Writer October 23, 2025

Chinese smishers — the bane of every American with a phone — have been shifting to lower-frequency, possibly higher-impact government impersonation attacks.

A large-scale smishing operation has been impersonating international brands across critical services in worldwide attacks.

Smishing has never been hotter than it is today, as more and more attackers have realized that texting is a quicker and more effective way to reach victims than email . As Verizon Business's vice president of global cybersecurity solutions Chris Novak told Dark Reading this week, "People tend to be more trusting of these devices," and less discerning texts than emails, "and as a result, they're more likely to click on links and follow through [with phishing logic]." Scammy alerts undelivered packages and unpaid tolls have now become a universal American experience. They always arrive from random, unidentified phone numbers, but the people behind these texts are very real, and not random at all.

The "Smishing Triad" has been known to the cybersecurity community for more than two years. In a new blog post, Palo Alto Networks' Unit42 demonstrated just how big it has become. The researchers pieced together a vast map of its infrastructure, revealing along the way patterns the group's latest targets, trends, and some changing tactics. For instance, it's been applying more nuance to its domain naming regimen, which might help it better evade notice.

The small number of loosely-defined threat groups now collectively referred to as the Smishing Triad dates back to at least 2023.

Its initial attacks took the form of easy-to-spot scam iMessages sent from compromised iCloud accounts instead of actual phone numbers. It hit its peak in 2025, thanks to a variety of new phishing-as-a-service (PhaaS) kits that use preloaded brand impersonation templates and even some embedded artificial intelligence (AI) features to make creating and distributing new malicious SMS campaigns a breeze.

The result was rampant, unremitting malicious activity. Between Jan. 1, 2024, and June 2025, Unit42 researchers identified 136,933 root domains registered by the Smishing Triad. 194,345 if you count each and every fully qualified domain name (FQDN). Reethika Ramesh, senior staff researcher for Palo Alto Networks, notes that her colleagues identified approximately 37,000 more FQDNs since it froze the data for its blog post in June. Each one represents some untold number of spam text messages. And to keep one step ahead of anyone trying to take them down, the Smishing Triad preemptively recycles its own infrastructure, usually within days of setting it up.

Source: Palo Alto Networks' Unit42

The scale of the Smishing Triad has naturally pushed it into more and more markets. At this point, it has spread spam across hundreds of countries: Malaysia to Ireland, Mexico to Australia, and Israel in between. But it knows where its bread is buttered. Since 2024, its focus has been primarily concentrated in the US.

Though certain delivery- and missing-payment-oriented lures have been go-tos, perhaps the sheer volume of attacks has required that the Smishing Triad diversify. Over time, it has impersonated German banks, Emirati police forces, British state-owned services, Lithuanian ecommerce platforms, plus social media sites, hospitality services, even carpooling apps.

The Smishing Triad is also diversifying its infrastructure. Take a look at the following chart, tracking the group's domain registration patterns by month:

Source: Palo Alto Networks' Unit42

On first glance, the chart might seem to depict a precipitous decline in newly registered domains. In reality, it's tracking only the top 10 domain prefixes used by the Smishing Triad. The triad uses prefixes as a way to compensate for not having the ideal domain for a brand impersonation attempt. The researchers wrote that, for example, "a casual inspection of the domain irs.gov-addpayment[.]info could trick people into thinking they are navigating to irs[.]gov."

With this in mind, two patterns become clear from the data. Where once the group preferred basic com- prefixes, the attackers are now heavily favoring gov-. Its phishing messages now often impersonate government agencies: the Internal Revenue Service (IRS) or, in variations on the toll theme, state Departments of Motor Vehicles (DMVs), and various other transportation related agencies.

More stark is the graph's sharp descent since March, indicating that "the domains associated with this campaign are continuously expanding, and they have evolved beyond solely utilizing these common prefixes," Ramesh says. "For instance, we started seeing more domains using US state names as prefix to impersonate state-level agencies and toll services, such as: virginia-govy[.]icu, ohio-govae[.]top, ny-govziu[.]vip, utah-govw[.]cc alongside hundreds of other similar domains registered in and after June 2025. We observed an increase in domains using prefixes that were previously less common, such as 'sim-', 'dmv-', and 'safety-'."

She notes that "the easier a pattern is to track, the faster they are going to be blocked. As a result, the attackers constantly evolve their domain naming and registration patterns to try and evade detection. This is why we think simple prefix-based blocking will not be enough to thwart them completely." In its blog post, Unit42 suggested that only more advanced URL filtering and domain name system (DNS) security will do the trick.

Nate Nelson, Contributing Writer

Nate Nelson is a writer based in New York City. He formerly worked as a reporter at Threatpost, and wrote "Malicious Life," an award-winning Top 20 tech podcast on Apple and Spotify. Outside of Dark Reading, he also co-hosts "The Industrial Security Podcast."

Miercom Test Results: PA-5450 Firewall Wins

Security Without Compromise Better security, higher performance and lower TCO

The Total Economic Impact™ Of Palo Alto Networks NextGeneration Firewalls

How Enterprises Are Harnessing Emerging Technologies in Cybersecurity

Worldwide Security Information and Event Management Forecast, 2025--2029: Continued Payment for One's SIEMs

The Cloud is No Longer Enough: Securing the Modern Digital Perimeter

Securing the Hybrid Workforce: Challenges and Solutions

Cybersecurity Outlook 2026

Threat Hunting Tools & Techniques for Staying Ahead of Cyber Adversaries

Measuring Ransomware Resilience: What Hundreds of Security Leaders Revealed

Extracted Entities

Attack Types (1)

Domains (1)

Industries (1)

Platforms (2)