Study Sheds Light on Shady World of Text Message Phishing Scams
NC State researchers have collected and analyzed an unprecedented amount of data on SMS phishing attacks, shedding light on both the scope and nature of SMS phishing operations.
Researchers have collected and analyzed an unprecedented amount of data on SMS phishing attacks, shedding light on both the scope and nature of SMS phishing operations. The work outlines techniques that can be used to collect additional data on phishing activities and identifies avenues that law enforcement officials can use to address phishing operations.
At issue is SMS phishing, which refers to attacks where scammers use text messages to try to trick people into sharing private information, such as credit card numbers or passwords, by impersonating a trusted party, like a bank or government agency.
To get around this limitation, the researchers used SMS gateways to obtain disposable phone numbers and waited for the numbers to receive phishing attacks. They monitored 2,011 phone numbers and identified 67,991 phishing messages over 396 days.
“In 2023, the world saw more phishing attacks than ever before, according to data from the Anti-Phishing Working Group,” said Alex Nahapetyan, first author of a paper on the study and a Ph.D. student in the Department of Computer Science.
“These attacks affect online security and privacy for consumers and can be extremely costly, but we have very little data on them. That’s because telecommunications companies are concerned about customer privacy and are reluctant to comb through the private data shared via text messages.”
Using text analysis, the researchers determined that those phishing messages could be divided into 35,128 unique campaigns, meaning that they were using virtually identical content. Further analysis found that those campaigns were associated with 600 distinct SMS phishing operations.
Some of the findings were surprising: SMS phishers are using mainstream servers, URL-shortening apps and web infrastructure to support their operations. Some phishers are also setting up their own domains to host their own URL-shorteners.
“This raises the possibility that the private URL shortening services provide some additional protection to phishers, or that this is a service being sold to phishers as part of the phishing ecosystem,” said
Nahapetyan.
The researchers also tested the defenses of telecom services by sending their own (harmless) phishing messages to 10 phone numbers from a privately owned phone, and again from a bulk messaging service. All of the phishing messages were delivered successfully. However, the bulk messaging service then banned the account.
The researchers looked for bulk messaging services that phishers would be able to use repeatedly, and they found them, not hiding in shadowy corners of the internet, but advertising openly on public social media platforms, such as LinkedIn.
“Altogether, the findings underscore two things,” said Nahapetyan.
“First, we already knew that there was an entire email phishing economy, and this work makes clear that this is true for SMS phishing as well. Someone can come in and buy an entire operation ready to go: the code, the URL, the bulk messaging, everything. And if their site gets shut down, or their messaging service gets banned, they don’t care. They’ll just move on to the next one,” said Nahapetyan.
“Second, we found that messages from many phishing operations include what appear to be notes to themselves. For example, a text may end with the words ‘route 7’ or ‘route 9’ or whatever. This suggests that phishers are using SMS gateways to test different routes for delivering phishing messages, in order to determine which routes are most likely to let their message through.”
In at least four instances, the researchers identified these “test messages” — including the URL the phishers were using — before the phishers had fully deployed their web infrastructure at the URL.
“This tells us that the messages were sent before the phishing attacks were launched in earnest. That’s important because it suggests that, by monitoring SMS gateways, we may be able to identify some phishing URLs before they roll their attacks out on a large scale. That would make those phishing campaigns easier to identify and block before any users share private data.”
The paper, “On SMS Phishing Tactics and Infrastructure,” was presented May 20 at the IEEE Symposium on Security and Privacy, which was held in San Francisco, Calif. Corresponding author of the paper is Brad Reaves, an associate professor of computer science at NC State. The paper was co-authored by Sathvik Prasad, a Ph.D. student at NC State; Kevin Childs, a former undergraduate at NC State; Alexandros Kapravelos, an associate professor of computer science at NC State; and Adam Oest and Yeganeh Ladwig of PayPal.
The research was done with support from the National Science Foundation, under grants 2142930 and 2047260; the North Carolina Partnership for Cybersecurity Excellence; the Office of Naval Research, under grant N00014-21-1-2159; funds from the 2020 Internet Defense Prize; and PayPal.
Note to Editors: The study abstract follows.
“On SMS Phishing Tactics and Infrastructure”
Authors: Aleksandr Nahapetyan, Sathvik Prasad, Kevin Childs, Alexandros Kapravelos and Bradley Reaves, North Carolina State University; Adam Oest and Yeganeh Ladwig, PayPal, Inc.
Presented: May 20 at the IEEE Symposium on Security and Privacy, San Francisco, Calif.
Abstract: In 2022, the Anti-Phishing Working Group reported a 70% increase in SMS and voice phishing attacks. Hard data on SMS phishing is hard to come by, as are insights into how SMS phishers operate. Lack of visibility prevents law enforcement, regulators, providers, and researchers from understanding and confronting this growing problem. In this paper, we present the results of extracting phishing messages from over 200 million SMS messages posted over several years on 11 public SMS gateways on the web. From this dataset we identify 67,991 phishing messages, link them together into 35,128 campaigns based on sharing near-identical content, then identify related campaigns that share infrastructure to identify over 600 distinct SMS phishing operations. This expansive vantage point enables us to determine that SMS phishers use commodity cloud and web infrastructure in addition to self-hosted URL shorteners, their infrastructure is often visible days or weeks on certificate transparency logs earlier than their messages, and they reuse existing phishing kits from other phishing modalities. We are also the first to examine in-place network defenses and identify the public forums where abuse facilitators advertise openly. These methods and findings provide industry and researchers new directions to explore to combat the growing problem of SMS phishing.
Adapted for the NC State Department of Computer Science, originally published in NC State News.
- Categories: