Rotating Front Ends, Static Backend: A 175-Day Smishing Operation
Rotating Front Ends, Static Backend: A 175-Day Smishing Operation
Since November 2025 one SMS smishing operator has run continuously, rotating every visible signal while a single backend fingerprint stays fixed. The sender numbers change. The domains change, one-shot and disposable, five to twelve per burner. The impersonated brand changes with the season: an auto-club roadside kit one month, a free meal box the next, then a Medicare dental-kit shipment, a paid clinical trial, a Pell Grant about to expire. What does not change is the backend. The same opaque tracking tokens appear on the new domains after every rotation, because rotating them would break the operator's own campaign accounting. That single stable substrate is what lets us treat an early progenitor burst and four later waves across 175 days as one operation, and it is the correlator that keeps catching the campaign after the sender-based signals go dark.
Key Takeaways
- A single SMS operator has run continuously since November 2025, cycling through a progenitor burst and four operational waves and eight impersonation pretexts while the backend infrastructure stayed constant.
- The durable correlator is a set of opaque tracking tokens carried in the click-through URL path and
?d=parameter. Roughly sixteen of them recur across new domains and new senders after every front-end rotation. - Front-end rotation is aggressive and multi-dimensional: 500+ burner senders across 12+ toll-free NANPA blocks, a mid-campaign expansion into five-digit shortcodes, and 1000+ single-use CTA domains.
- CTA domains are coined, pronounceable four-to-ten-character
.comstrings registered under WHOIS privacy at two registrars, most minted days before use, some aged and held dormant for months before activation. - A subset of links carry a callback phone number in a
?pc=parameter, routing tapped recipients into a pay-per-call vishing operation. Those callback numbers are the longest-lived operator-controlled indicators in the set. - The operator stayed strictly SMS-exclusive across the full window. A 180-day content and token search of email traffic returned zero crossover.
Background
The operation reads as a business, not a burst. It has run for more than 175 consecutive days with smooth wave-to-wave handoffs, stable supplier relationships for toll-free numbers and domains, and a backend that behaves like a lead-management or pay-per-call CRM. Across that window it produced tens of thousands of scam text messages aimed at US consumers, with lure framing that leans repeatedly on Medicare-eligible audiences.
The brand portfolio is chosen, not random. Each pretext borrows a high-recognition US consumer brand whose marketing an average recipient cannot verify in the moment: AAA (marketed here as TripleA) for a free roadside kit, ButcherBox for a free meat box, Medicare and UnitedHealthcare for account-fraud and dental-kit shipments, Oral-B as the premium freebie attached to the dental lure, Pell Grant for students. The operator avoids brands with strong out-of-band verification, such as banking apps that push their own notifications. That selection bias is itself a fingerprint.
Two rails carry the traffic. The senders sit on application-to-person (A2P) messaging: US toll-free long codes provisioned through resellers that allocate numbers in batches, and later a set of five-digit shortcodes obtained through a separate procurement channel. Toll-free numbers and shortcodes are the legitimate rails for bulk business texting, which is exactly why a smishing operator wants them. On the click side, every message hands off to a disposable domain that carries a tracking token and, in a subset of cases, a callback phone number. The domain is throwaway. The token is not.
Sender-based blocking is brittle against an operator who can buy new number blocks, switch to shortcodes, or move to a new toll-free prefix. Domain-based blocking is equally brittle when every domain is used once and burned in one to three days. The tracking tokens survive both, because they are the keys the operator uses to attribute conversions and pay affiliates. Rotating them would break the money pipeline, so they stay put.
Discovery and Infrastructure
The campaign first surfaced as a three-sender burst impersonating TripleA and ButcherBox. A retrospective sweep keyed on the durable tokens and callback numbers then extended the operator's documented timeline five months backward and resolved the activity into a progenitor burst and four waves. Each wave cycles a fresh toll-free block and a refreshed domain pool while preserving the backend.
| Wave | Approximate window | Primary sender blocks | Lures | Sender type |
|---|---|---|---|---|
| W0 (progenitor) | Nov 2025 to Dec 2025 | +1-833-406-XXXX, one Ohio area-code outlier |
TripleA giveaway, Medicare account-flagged | Toll-free |
| W1 | Dec 2025 to Jan 2026 | +1-833-832-XXXX, +1-833-588-XXXX, +1-833-516-XXXX |
Loan and credit approval, overpayment refunds | Toll-free |
| W2 | Jan 2026 to Mar 2026 | +1-833-836-XXXX, +1-833-951-XXXX, +1-833-984-XXXX |
TripleA reintroduced, dental-kit precursor, credit approval | Toll-free |
| W3 | Mar 2026 to Apr 2026 | +1-833-697-8XXX, +1-833-984-2XXX |
UNHC dental kits, clinical trials, Pell Grant, overpayment | Toll-free |
| W4 | Apr 2026 onward | Five-digit shortcodes, +1-866-382, +1-844-966, +1-844-664 |
UNHC dental kits, clinical trials, overpayment | Shortcode and toll-free |
The wave boundaries expose the operator's tempo. Each block runs roughly 30 to 45 days before it is exhausted or rotated ahead of carrier blocking, and transitions overlap by several days rather than cutting over abruptly. Overlap is the tell that the operator provisions the next reseller block before retiring the current one, which is what a resourced, forward-planning operation does.
W4 is the most instructive transition. The sender-pattern query that had tracked the +1-833 blocks returned nothing new once the operator moved to shortcodes and the +1-866 and +1-844 prefixes. The token correlator was the only signal that carried across the gap. It caught continuation on three brand-new domains through new shortcodes and a new toll-free number, with the same tokens intact. That is the empirical case for token-based correlation: everything the operator could rotate for evasion, it rotated, and the backend still gave it away.
How It Works
A single message does the whole job in one line. It opens with a brand tag (TripleA:, UNHC:, ButcherBox), personalizes with the recipient's first name, and manufactures urgency: a gift held until a date, a balance already owed, a benefit about to expire, a specific dollar amount. Then it hands off to a short link on a disposable domain.
The link is the pivot. It resolves to a landing page built to harvest the fields that give a record market value, or in the pay-per-call variant it fronts a callback number that routes the recipient to a live vishing script. The refund and credit lures cite oddly precise amounts rather than round numbers, because precision reads as a records-system output. A stated balance of a few hundred dollars and change feels retrieved; a round figure feels advertised.
The content carries a consistent obfuscation layer. Throughout the campaign the operator substitutes a capital I for a lowercase l, producing tokens like baIance, PAlD, triaI, PriorityIoan, and fIagged, and drops letters in words like govermnt. The substitution is human-readable but defeats naive keyword matching. It is not a late-stage reaction to filter pressure. The earliest documented instance, a Medicare account-flagged lure, predates the main waves by months, which makes it a baseline operator standard rather than an evolution.
Sample Lures
Every sample below is a real message with recipient PII removed. Recipient first names are replaced with [name], per-recipient tracking tokens with [id], and victim-specific figures with $[amount]. All operator domains are defanged. Attacker-side content, the brand tag, pretext, and link grammar, is preserved. Note the capital-I-for-l substitution running through several of them.
Auto-club roadside-kit pretext (W0 through W2 revival, name personalization):
TripleA: [name], your Roadside Kit welcome gift is still available today.
Claim it before 03/08 http[:]//savnwoffr[.]com/go Text Stop To Opt Out
Free-meal-box pretext (routed through a burner, never the brand's real shortcode):
ButcherBox is offering a limited free box for you. Claim yours today.
offer expires 3/8. http[:]//bboxr[.]com/nCl/[id]
Dental-kit shipment pretext (impersonating UnitedHealthcare, first seen late March):
UNHC: your complimentary Oral B dental kit is awaiting shipment.
http[:]//getzofr[.]com/bit
Overpayment-refund pretext (the dominant continuation theme, obfuscated content and fabricated precise balance):
You have a OVER-PAlD baIance of $[amount]. Confirm to release your refund.
[defanged burner domain]/[id]
Loan and credit-approval pretext (rebranded as FastFunds and PriorityIoan):
[name], your FastFunds are locked in. Your PriorityIoan is confirmed.
[defanged burner domain]/[id] - Stop to End
Paid-clinical-trial pretext (introduced April, heavy obfuscation):
Get PAlD $[amount] for a simpIe clinicaI triaI in your area.
http[:]//clinltr[.]com/[id]
Medicare account-flagged pretext (November 2025, earliest documented obfuscation):
HelIo [name], your Medicare check fIagged for review. Pending update needed.
[defanged burner domain]/[id]
Technical Analysis
The Durable Backend Fingerprint
The strongest evidence that these dissimilar-looking waves are one operator is token reuse. The click URLs carry opaque identifiers in two positions: an eight-to-ten-character token in a ?d= query parameter, and shorter tokens embedded as path segments. These tokens are stable while everything around them rotates. The same identifier appears on an original-wave domain and, weeks later, on a fresh continuation domain sent from a different burner and a different sender type.
| Token | Position | Appears across |
|---|---|---|
uPFjccjj9 |
?d= param |
original-wave and continuation domains, multiple senders |
ukWBHGDvc |
?d= param |
continuation domains across shortcode and toll-free senders |
uPwKNuphK |
?d= param |
continuation domains, spans a sender-type change |
bkTPn-j |
path segment | roughly ten continuation domains in the credit and finance vertical |
BbQtgfz |
path segment | original meal-box and continuation domains, 8+ days apart |
BWzVTfT |
path segment | auto-credit continuation domains |
The interpretation is that a single backend, most likely a self-hosted lead-management or pay-per-call CRM, generates tracking URLs with fixed per-campaign identifiers. Roughly sixteen such tokens have collectively persisted for more than 150 days. They are the campaign's most reliable correlator and the one that caught the W4 transition when sender and domain queries could not.
Pay-Per-Call Callback Infrastructure
A subset of links carry a callback phone number directly in a ?pc= parameter set to an E.164 number. A recipient who taps the link is routed through the disposable domain to a handler that initiates a return-call lure to that number. These callback numbers rotate far more slowly than senders or domains, because each one fronts a real call-handling operation that has to stay reachable long enough to convert. One Oregon-area callback number stayed live across a six-week span and appeared on nineteen distinct finance-themed domains. The geographic spread of the numbers (Oregon, Kentucky, Florida, Kansas, Texas) reflects leased call-routing endpoints, not the operator's location. The presence of a ?pc= callback parameter is itself a strong per-message signal and points to a pay-per-call monetization model, where every completed call is a revenue event the backend has to track.
Domain-Generation Grammar
The CTA domains are coined, pronounceable, four-to-ten-character .com strings, with occasional .co and .link variants. The naming falls into consistent theme-keyed families that track the lure:
- Savings and payment: the
pay*ofr,sav*ofr, andget*ofrfamily, with more than fifteen variants (paynwoffr[.]com,savnwoffr[.]com,getzofr[.]com). - Finance:
*fin*,*cred*,*fund*, and*loan*roots (atocred[.]com,autocreds[.]com,truefintx[.]com,fundrica[.]com). - Health and clinical:
*cln*,*med*,*hlth*roots (clinltr[.]com,clintrlls[.]com,medcrtdy[.]com). - Auto and insurance:
auto*,*car*, and vowel-dropped credit roots (autocreds[.]com,atcarstop[.]com,alloncars[.]com).
The domain inventory is one-shot and disposable, which is why domain-level blocklists have little leverage here. The naming grammar, by contrast, is stable across all 175 days and is a usable proactive signal when combined with the scam classification of the traffic.
Registration Cohorts and Aged-Domain Staging
Public WHOIS separates the inventory into a fresh-burn cohort and an aged-staged cohort, and the mix is the interesting part. Most domains are registered under WHOIS privacy days before first use. A minority were registered months earlier and held dormant, then activated in a later wave, which blunts age-based reputation signals.
| Domain | Registrar (privacy) | Created | First seen in traffic | Cohort |
|---|---|---|---|---|
nexovacr[.]com |
Namecheap | 2025-10-29 | Apr 2026 (W4) | Aged-staged |
xdrivecare[.]com |
Namecheap (Withheld for Privacy) | 2025-11-12 | Apr 2026 (W4) | Aged-staged |
brightlinesg[.]com |
Namecheap (Withheld for Privacy) | 2026-01-14 | 2026-04-20 (W4) | Aged-staged |
smilenhst[.]com |
Namecheap (Withheld for Privacy) | 2026-02-03 | 2026-04-20 (W4) | Aged-staged |
savnwoffr[.]com |
Namecheap (Withheld for Privacy) | 2026-03-06 | 2026-03-08 (W3) | Fresh burn |
selfdents[.]com |
Namecheap (Withheld for Privacy) | 2026-03-06 | 2026-03-08 (W3) | Fresh burn |
asoneken[.]com |
Registrar.eu (WHOIS Privacy Foundation) | 2026-03-11 | 2026-03-11 (W3) | Fresh burn |
rezband[.]com |
Namecheap (Withheld for Privacy) | 2026-04-03 | 2026-04-18 (W4) | Short hold |
clinltr[.]com |
Namecheap | 2026-04-01 | Apr 2026 (W3) | Fresh burn |
Two registrars carry the whole inventory: Namecheap behind Withheld for Privacy, and Hosting Concepts B.V. trading as Registrar.eu behind the WHOIS Privacy Protection Foundation. The staging is the defense-relevant detail. A domain registered in late October or early November and first appearing in SMS traffic five to six months later is a deliberate way to defeat a reputation input that treats registration age as a proxy for safety.
Front-End Diversification Over Time
The operator has widened its sender procurement over the campaign. It began on +1-833 toll-free long codes, then added +1-866 and +1-844 toll-free prefixes, then introduced five-digit shortcodes as a distinct sender-type class. Shortcode provisioning runs through a different supply chain than toll-free numbers, so the addition implies either a new reseller relationship or an affiliate relay stepping in. Through all three shifts the backend tokens were unchanged, which places the shortcodes and the new toll-free prefixes inside the same operation rather than alongside it.
Detection Observations
The following behaviors separate this operator's traffic from legitimate business texting. They are framed as signals a defender can key on.
- The durable tracking tokens in the URL path and
?d=parameter are the single strongest cross-rotation pivot. A token match is high-confidence for this operator regardless of sender, sender type, domain, or number block. - A callback number carried in a
?pc=URL parameter is anomalous in ordinary SMS marketing and marks the pay-per-call vishing variant. - The capital-
I-for-lowercase-lsubstitution (baIance,PAlD,triaI,PriorityIoan,fIagged) and dropped-letter spellings (govermnt) are persistent content markers that survive every front-end change. - A brand tag paired with a toll-free number or shortcode that is not the brand's real messaging channel is a reliable tell. Legitimate senders use their own registered shortcodes; the meal-box brand this operator imitates markets from a specific five-digit code, never from a toll-free burner.
- Coined, pronounceable
.comdomains under WHOIS privacy at Namecheap or Registrar.eu, registered within days of first use and paired one-to-one with a single sender, fit the operator's provisioning pattern. - Aged domains appearing in traffic for the first time months after registration deserve scrutiny. Registration age alone is not a safety signal against an operator that stages inventory.
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3), available at https://ctid.mitre.org/fraud. Technique names below are drawn from the F3 vocabulary; the framework is the authoritative reference for identifiers.
| Tactic | Observed technique |
|---|---|
| Resource Development | Batch acquisition of toll-free numbers and shortcodes through A2P resellers; bulk registration of coined .com domains under WHOIS privacy, including aged-domain staging |
| Initial Access | Smishing (SMS phishing) with per-brand tags and short-link redirects |
| Initial Access | Impersonation of high-recognition consumer brands (auto club, meal box, Medicare, health insurer) and manufactured account or benefit context |
| Execution | Urgency and reward framing (expiring gifts, fabricated refunds, benefit deadlines) and per-recipient personalization driving click-through |
| Monetization | Harvesting of identity and financial PII via landing-page intake forms |
| Monetization | Pay-per-call vishing via ?pc= callback numbers and lead resale through a shared backend CRM |
| Stealth | Continuous rotation of senders, domains, sender types, and number blocks over a fixed backend |
Indicators of Compromise
All indicators below are defanged. Recipient data has been removed. Aggregate totals are stated as verified-malicious floors, not exact counts. The two callback-number and tracking-token sets are the durable, long-lived correlators; the sender and domain sets are representative subsets of a much larger disposable inventory.
Sender Phone Numbers (Toll-Free Burners)
| Value | Role | Notes |
|---|---|---|
+1-833-697-8631 |
Sender | W3 burner block |
+1-833-697-8613 |
Sender | W3 burner block |
+1-833-697-8533 |
Sender | W3 burner, high per-burner volume |
+1-833-984-2075 |
Sender | W3 burner block |
+1-833-984-2428 |
Sender | W3 burner block |
+1-833-406-5890 |
Sender | W0 progenitor block |
+1-833-832-8939 |
Sender | W1 finance wave |
+1-866-382-4536 |
Sender | First burner outside +1-833, caught via token pivot |
+1-844-966-5012 |
Sender | W4 diversification block |
+1-844-664-4044 |
Sender | W4 block, nine domains in a single day |
+1-866-412-1609 |
Sender | W4 block |
| … | (representative subset; part of a 500+ burner-sender footprint across 12+ toll-free NANPA blocks) |
Sender Shortcodes (Five-Digit)
| Value | Role | Notes |
|---|---|---|
51821 |
Sender | W4 shortcode, tokens uPFjccjj9 / uPwKNuphK / ukWBHGDvc |
63426 |
Sender | W4 shortcode, token ukWBHGDvc |
353257 |
Sender | Branded clinical-trial variant |
47894 |
Sender | Pharma-themed cluster |
989454 |
Sender | Twin-domain cluster |
27204 |
Sender | Continuation shortcode |
34793 |
Sender | Continuation shortcode |
| … | (representative subset; the operator diversified into roughly 50 shortcodes) |
Callback / Vishing Numbers (Durable)
| Value | Role | Notes |
|---|---|---|
+1-503-490-8880 |
Callback | Longest-lived; 19 finance domains over ~6 weeks |
+1-606-945-0991 |
Callback | W3 to W4 successor |
+1-813-850-2155 |
Callback | Parallel to the 503 cycle |
+1-316-559-6586 |
Callback | W2 predecessor |
+1-352-282-2727 |
Callback | One-day overlap with the 503 number |
+1-817-771-0811 |
Callback | W3 finance chain |
Domains (CTA Landing / Redirect)
| Value | Role | Notes |
|---|---|---|
savnwoffr[.]com |
CTA | W3, roadside-kit lure; Namecheap 2026-03-06 |
bboxr[.]com |
CTA | Meal-box impersonation; Namecheap 2026-03-08 |
selfdents[.]com |
CTA | Medicare/medical lure; Namecheap 2026-03-06 |
asoneken[.]com |
CTA | Credit-approval lure; Registrar.eu 2026-03-11 |
efinatco[.]com |
CTA | Finance lure, early callback host |
getzofr[.]com |
CTA | Dental-kit lure |
clinltr[.]com |
CTA | Clinical-trial lure; Namecheap 2026-04-01 |
clintrlls[.]com |
CTA | Clinical-trial lure; Namecheap 2026-04-01 |
autocreds[.]com |
CTA | Auto-credit lure |
fundrica[.]com |
CTA | Finance lure, callback chain |
rezband[.]com |
CTA | W4 shortcode landing; Namecheap 2026-04-03 |
smilenhst[.]com |
CTA | W4 dental lure; aged-staged, registered 2026-02-03 |
brightlinesg[.]com |
CTA | W4 landing; aged-staged, registered 2026-01-14; operator-coined, unaffiliated with any similarly named brand |
nexovacr[.]com |
CTA | W4 landing; aged-staged, registered 2025-10-29 |
xdrivecare[.]com |
CTA | W4 landing; aged-staged, registered 2025-11-12 |
eynmia[.]com |
CTA | Branded clinical-trial variant |
| … | (representative subset; 1000+ verified-malicious CTA domains, one-shot and disposable) |
Durable Tracking Tokens (Monitoring Correlators)
?d= parameter: uPFjccjj9 ukWBHGDvc uPwKNuphK uPdXTJqNw uPuCrjyXL uPvGhVgKF
path segment: BbQtgfz bkTPn-j BWzVTfT BmnwhXm wWTPvv TxJldP iA0fET
Lure-Body Markers
brand tags: TripleA: / UNHC: / ButcherBox
obfuscation: baIance / PAlD / triaI / PriorityIoan / FastFunds / fIagged / govermnt
URL shapes: <burner>/<3-letter-path> <burner>/<slug>?d=<token> <burner>/?pc=<callback>
Conclusion
The durable asset here is the backend, not the front end. Senders, domains, brand tags, and even the sender-type class are all consumable, and the operator has demonstrated it will replace any of them the moment they draw pressure. The tracking tokens and callback numbers persist because they carry the money. That asymmetry is the opening for defenders: front-end blocking buys days, while a token or callback match holds across every rotation the operator has shown it can execute. Watch the backend correlators, watch for aged domains surfacing long after registration, and treat a brand tag on a channel the brand does not use as the contradiction it is.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.