Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns
Essential information
- Published
- 29/04/2026 12:31
- Modified
- 04/05/2026 10:59
- Tags
- 2026-04-29 bts injection credential harvesting financial fraud mfa bypass phaas phoenix system smishing
- Related entities
- 24 observables, 3 techniques (mitre), 3 others
Description
Since January 2025, researchers identified over 2,500 phishing domains targeting more than 70 organizations across financial services, telecommunications, and logistics sectors globally. Two dominant smishing campaigns were discovered: Reward Points phishing impersonating banks and telecom providers, and Failed Parcel Delivery phishing mimicking logistics companies. Despite different themes, both campaigns share infrastructure and utilize the Phoenix System administrative panel, a successor to the Mouse System. This Phishing-as-a-Service platform offers real-time victim monitoring, geofencing, IP-based filtering, and live-phishing interventions to bypass multi-factor authentication. The platform is distributed via Telegram channels for approximately $2,000 annually, providing threat actors with pre-built templates, traffic filtering mechanisms, and real-time victim management dashboards. Attackers potentially leverage fake Base Transceiver Stations to bypass carrier-level filtering and deliver messages app...