Burner Numbers and Shared Scripts: An SMS Pig-Butchering Network
Burner Numbers and Shared Scripts: An SMS Pig-Butchering Network
Since July 2025, more than 100 burner phone numbers have run a coordinated SMS romance and pig-butchering operation held together by shared scripts. Each number talks to a single victim at a time, building a fake relationship over days or weeks before steering the conversation toward crypto, gift cards, and wire transfers. There are no links to click and no landing pages to fingerprint. The entire scam, from a "wrong number" opener to a step-by-step instruction to send $49,700 in Bitcoin, happens in plain conversational text. What ties these otherwise-anonymous numbers into one operation is not infrastructure in the usual sense but language: the same verbatim phrases surface across numbers that share nothing else, and the same Texas area codes appear again and again.
Key Takeaways
- This operation runs one disposable US mobile number per victim in sustained one-on-one conversations, the inverse of bulk smishing, so per-number volume stays low enough to slip bulk-sender heuristics.
- The strongest cross-actor clustering signal is verbatim shared scripting: identical phrase families such as "my management," "good morning my love," and "cash app to verify" recur across numbers that otherwise have no overlap.
- Every message is URL-free, so the whole lifecycle defeats URL reputation and link-based scanning by never presenting a link at all.
- Sender numbers cluster hard in Texas, roughly a quarter of all actors and Houston alone at 14%, which points at a shared number-procurement pool rather than a hundred independent scammers.
- The dual signal of romantic endearment vocabulary and financial-instruction vocabulary from the same number is the near-perfect discriminator between this scam and a genuine relationship.
- Migration off SMS has drifted over the campaign from WhatsApp and iMessage toward obscure encrypted apps like Zangi, chosen for lower monitoring.
Background
Pig butchering takes its name from the Chinese phrase sha zhu pan, "pig-slaughtering plate." The operator spends weeks "fattening" a victim with attention and affection, then steers them into a fabricated investment or a chain of payment requests and drains everything at once. The category emerged around 2019 and is now the largest crypto-scam type by value, run at scale from industrial "scam compounds" in Southeast Asia that depend on trafficked, debt-bonded labor. The numbers are hard to overstate. The FBI's Internet Crime Complaint Center attributed roughly $5.8B in 2024 losses to crypto-investment fraud, and in October 2025 the Department of Justice moved to seize about $15B in Bitcoin tied to a single Cambodia-based network that allegedly ran phone farms and forced-labor camps.
The SMS variant documented here is the front door to that machine. It opens with the hallmark of the genre: an unsolicited "wrong number" or mistaken-reconnection text, engineered so that a polite correction from the target starts a conversation the operator can cultivate. From there the playbook is pure social engineering conducted over ordinary text messages.
A few pieces of the surrounding ecosystem are worth naming, because the operation leans on legitimate services at every stage:
- Disposable US phone numbers come from VoIP, MVNO, prepaid, and number-app pools of the TextNow and Google Voice class. These are legitimate services that hand out real US numbers over the internet with no verified subscriber behind them. Operators provision them in bulk, use each briefly, and discard it, so any single number burns out fast and the trail dead-ends at a throwaway account rather than a person.
- Encrypted messengers are the destination the operator wants. Pushing a target off carrier SMS onto WhatsApp, iMessage, Telegram, Signal, or a lesser-known app like Zangi removes carrier-level and app-level message scanning from the picture. The richer app environment also enables video calls to "prove" a fake identity, image sharing for fabricated trading dashboards, and deletable messages that erase evidence.
- Crypto on-ramps such as Coinbase and Uphold, P2P apps such as Cash App, Chime, and Zelle, and Apple gift cards are the extraction rails. They are chosen for irreversibility. On-chain transfers cannot be clawed back, P2P transfers clear near-instantly with little recourse, and a gift-card code is spent the moment it is read aloud. None of these companies is complicit; each is a legitimate business being abused as a fast, hard-to-reverse cash-out path.
Discovery and Infrastructure
The cluster surfaced from a seed of phone numbers already tagged as romance-scam senders. Pivoting on their behavior produced a repeatable signature: US +1 mobile numbers, no URLs anywhere in the message stream, financial-instruction language emerging mid-conversation, and sustained multi-day activity against what looked like a single conversational partner. That signature alone was not enough, because it overlaps heavily with legitimate personal texting and with other text-only scams like bank-alert and debt-collection smishing. The refinements that produced high-precision hits were a direct search on the romance vocabulary and, best of all, a dual-signal search for numbers that emit both romantic endearments and financial instructions. A number that says both "good morning my love" and "download coinbase" is almost never a real relationship.
Across the nine-month window from July 2025 into 2026, the operation spans more than 100 distinct sender numbers and tens of thousands of messages. There are no domains, no hosts, and no URLs to inventory, which makes this campaign a useful counterpoint to link-based phishing: the indicators are numbers, phrases, and behavior, not infrastructure.
How It Works
The lifecycle runs in seven phases, and it can take weeks to months end to end.
Initial contact opens with a wrong-number or misdial text, a claimed reconnection ("It's me Patrice," followed by an excuse like "this just my google private number"), or a direct romantic approach. The message reads as a personal text, not a marketing blast, which is the point.
Grooming and trust-building runs three to fourteen days in the conversations we can see, and likely longer in the ones we cannot. The operator floods the target with endearments and daily check-ins, and stages "verification theater" by proactively offering photos as proof of identity, typically stolen images.
Platform migration comes early. The operator pushes the target off SMS onto an encrypted app, framed as convenience ("I will try and set up WhatsApp") but chosen to escape monitoring.
The financial pivot introduces money through one of five pretext families: an emergency or urgent need, funds to travel and finally meet, a crypto-investment "opportunity," a VIP or exclusive-access card, or a payment-verification advance fee. Each frames the request as urgent, temporary, or mutually beneficial.
Direct extraction is where the operator's patience pays off. The instructions are unusually detailed because many targets have never used crypto. The operator walks them through downloading an app, signing into an account, and sending funds to a wallet the operator controls.
Retention keeps a hesitating victim in the scheme through guilt-tripping, gaslighting, false assurance, and isolation. The DARVO move (deny, attack, reverse victim and offender) is striking here, with the operator accusing the victim of being scammed to deflect suspicion.
Post-extraction, the operator either requests more with a fresh pretext, ghosts once the victim is exhausted, or reappears later from a new number to restart the cycle with the same persona.
Sample Lures
All samples below are redacted. Recipient identifiers have been removed and replaced with placeholders. These are attacker-side messages only.
Reconnection opener (the "wrong number" and false-familiarity entry):
From: +1 (XXX) XXX-XXXX (unknown mobile)
"Hi dear"
"Good day how's your Sunday going"
"Hope no offense me messaging [recipient name] been so..."
"It's me Patrice"
"Nope this just my google private number"
"It's been since last year we chatted last"
Grooming and love-bombing (daily-cadence emotional investment before any money is mentioned):
From: +1 (XXX) XXX-XXXX (unknown mobile)
"Good morning my love"
"How was work baby"
"Am glad you got some peaceful sleep sweetheart"
"My king!"
"Ok my love. I will try and set up WhatsApp"
"I can't wait to finally meet you, my love"
Financial pivot and crypto walkthrough (the advance-fee and pig-butchering extraction, blended with reassurance):
From: +1 (XXX) XXX-XXXX (unknown mobile)
"Can you add $40 to your Cash App to verify..."
"You are to deposit $169 for PVC charges to release [the payment]..."
"The $169 will be sent back to you ten minutes [later]..."
"First you will download coinbase to your [phone]..."
"Click on Send crypto to friends and family"
"And then put the 1100 in bitcoin tomorrow"
"Would you get me the Apple Card of 500"
"I swear on my life and everything once you [deposit]..."
Technical Analysis
The moat in a URL-free campaign is behavioral and linguistic. These fingerprints tie a hundred anonymous numbers into a single operation and separate the scam from genuine texting.
Number Infrastructure and Rotation
The channel shape is narrow and consistent: US +1, ten-digit mobile numbers only. No shortcodes and no alphanumeric sender IDs ever appear. This is the inverse of bulk smishing, where one sender blasts thousands of recipients. Here, one number maps to one victim in a sustained conversation, then is retired. Observed active windows run from single-day bursts to sustained operations of 26 and 47 days. The deliberately low per-number volume is itself an evasion: it keeps each number under the thresholds that catch bulk senders. When a persona is ghosted, it can reappear on a fresh number to restart the cycle, which we observed with a reused "Patrice" persona jumping to a second number.
Geographic Clustering
Sender numbers cluster hard by area code, and the clustering is the single strongest procurement-source signal in the dataset. A hundred independent scammers would scatter across the North American Numbering Plan. This set does not.
| Cohort | Area Codes | Actors | Share |
|---|---|---|---|
| Houston, TX | 281 / 346 / 832 | 14 | 14% |
| Dallas, TX | 469 / 214 | 7 | 7% |
| San Antonio, TX | 210 | 3 | 3% |
| Los Angeles, CA | 213 / 626 | 5 | 5% |
| New Jersey | 201 / 908 | 4 | 4% |
| Other US | various | 67+ | 67% |
Texas accounts for roughly a quarter of all actors, with Houston alone at 14%. That concentration is consistent with a shared Texas-pool VoIP or MVNO source, or a physical operation base in the Houston area. A few non-US strays sit in the tail (an Australian +61 and a Dutch +31 among them), hinting at an international variant of the same playbook.
Shared-Script Fingerprinting
The clearest evidence of coordination is verbatim shared scripting. The same phrases appear across numbers that share no other attribute, which is what you would expect from operators reading off a common playbook rather than improvising.
| Phrase (or Phrase Family) | Distinct Senders | Role |
|---|---|---|
| "good morning my love" | 6 | Canonical grooming opener |
| "uphold" (as an in-message rail) | 31 | Shared extraction-platform scripting |
| "wrong number" (misdial opener) | 18 | Shared pig-butcher entry pretext |
| "cash app ... verify" | 6 | Shared advance-fee verification script |
| "my management ..." (controls that / won't approve this trip) | 4 | Shared isolation and travel pretext |
| "apple card of 500" | 2 | Identical gift-card amount and phrasing |
| "swear on my life" | 2 | Shared reassurance and retention line |
The "my management" family is the most telling. Variants like "my management controls that" and "my management won't approve this trip" recur across at least four unrelated numbers, casting an off-screen authority that both explains delays and pressures the victim. Shared scripting at this level of verbatim overlap is a coordination signal, not a coincidence, and it is the pivot that links seemingly independent actors.
Linguistic and Dual-Signal Fingerprints
Grammar is a fingerprint. Tense and agreement errors recur in ways that read as a consistent non-native-English hand: "Did uphold replied your email already love?", "Verified the identity yet love?", "Have you called the bank Love?". The endearment lexicon is small and heavily reused: love, my love, baby, sweetheart, honey, my king, darling, dear, delivered at high frequency and often several times a day.
The most operationally useful signal is co-occurrence. A number that emits only endearments could be a real partner; a number that emits only financial vocabulary could be any transactional sender. The same number emitting both, the endearment lexicon alongside bitcoin, coinbase, uphold, cash app, chime, deposit, verify, fund, and wire, is the near-perfect discriminator. That co-occurrence is what makes an otherwise-invisible grooming conversation classifiable.
The Financial Escalation Ladder
The ask starts small and climbs. The first request is a "verification" or "test," often $40 to $169, including the recurring "$169 for PVC charges" line paired with a promise that the money returns "ten minutes later." Compliance opens the door to mid-tier requests of $500 (typically an Apple gift card), $1,100, and $1,500. In the pig-butchering variant, a fabricated dashboard shows fake returns to justify larger deposits, and the endgame runs to $10,000 to $50,000 and beyond. A single observed instruction line reads "you are sending $49,700."
| Rail | Role in the Scam | Typical Amount |
|---|---|---|
| Bitcoin / generic wallet | Primary pig-butcher extraction | $1,100 - $49,700 |
| Coinbase | Crypto on-ramp, operator-supplied credentials | Varies |
| Uphold | Alternative crypto platform | Varies |
| Cash App | Quick small-to-medium transfers | $40 - $3,000 |
| Chime | Alternative digital-banking transfer | Varies |
| Apple Card / gift cards | Small-to-medium, instantly redeemable | $500 |
| Wire transfer | Large-sum extraction | $1,500 - $49,700 |
| PayPal / Zelle | Occasional | Varies |
A recurring detail: the operator demands screenshots "as confirmation" of each payment. Those screenshots double as balance reconnaissance, sizing the victim's account for the next ask.
Platform Migration Over Time
Migration off SMS is near-universal, but the destination has shifted over the campaign. Ranked by how often each app is referenced across the message stream, the picture is:
| Target | Role |
|---|---|
| Dominant migration target | |
| Snapchat | Common secondary target |
| Telegram | Recurring target |
| Google (chat / voice) | Occasional, and sometimes discouraged |
| Zangi | Newer pivot, appearing from late November 2025 |
| Messenger | Usually steered away from |
| iMessage | Rarely observed |
Two behaviors stand out. First, the operator actively steers away from some platforms ("I don't chat on messenger sweetheart," "or google due to my past experiences"), a selection process rather than a blanket push. Second, the Zangi pivot is new. Earlier engagements move to mainstream encrypted apps, but from late November 2025 a lesser-known encrypted messenger enters the rotation, chosen precisely for its obscurity and lower monitoring. That drift toward niche apps is the trend defenders should track.
Detection Observations
This campaign is defined by what it lacks. With no URLs, no links, and no attachments, the usual link-reputation and payload signals never fire. Recognition has to come from behavior and language.
The grooming phase is the hardest to separate from genuine texting. In isolation, "Good morning my love" and "Miss you honey" are indistinguishable from a real relationship, which is exactly why the operators lead with them. The signal sharpens as the conversation progresses. The single most reliable behavioral marker is the dual signal already described: romantic endearments and financial-instruction vocabulary emitted by the same number. Layered on top of that, three attributes make a conversation easier to recognize: a US +1 mobile number sustaining a one-to-one exchange with no links over multiple days, verbatim script phrases shared with other flagged numbers, and the non-native grammar tells. An urgent push to migrate to an encrypted app, especially an obscure one, early in a relationship is a further tell.
The cross-actor pivots matter more than any single message. Shared scripting and area-code cohorts let a defender connect a newly-seen number to a known cluster before that number has done anything overtly financial, which is the window where intervention still helps the target.
Indicators of Compromise
All indicators below are defanged and drawn from the verified-malicious set. Recipient data has been removed. This is a representative subset of sender numbers, not the full inventory. There are no domains, hosts, or URLs in this campaign.
Sender Phone Numbers
| Value | Role | Notes |
|---|---|---|
+1-252-628-9056 |
Sender | Highest-volume actor, 26-day crypto extraction |
+1-424-901-1381 |
Sender | Bitcoin and Uphold extraction, bank manipulation |
+1-626-515-6108 |
Sender | Longest sustained operation, 47 days |
+1-401-237-0436 |
Sender | Sustained grooming and extraction |
+1-302-231-5296 |
Sender | Multi-week operation |
+1-516-830-3501 |
Sender | Recent, Chime payments, travel pretext |
+1-619-468-7375 |
Sender | Short-burst operation |
+1-801-845-7448 |
Sender | Single-day high-volume burst |
+1-448-210-2060 |
Sender | Grooming-only phase, WhatsApp migration |
+1-972-737-0310 |
Sender | Short-burst operation |
+1-580-264-1248 |
Sender | Cash App advance-fee variant |
+1-209-498-7359 |
Sender | Bitcoin, Apple Card, Chime, adoption pretext |
+1-339-244-6492 |
Sender | VIP-card pretext |
+1-501-382-3675 |
Sender | Reconnection attempt, "Patrice" persona |
+1-708-247-5914 |
Sender | Pig butchering, Coinbase, $49,700 instruction |
| ... | representative subset; hundreds of verified-malicious sender numbers |
MITRE Fight Fraud Framework Mapping
The mapping aligns to MITRE's Center for Threat-Informed Defense fraud framework (https://ctid.mitre.org/fraud), which organizes cyber-enabled fraud into tactics and cross-references MITRE ATT&CK technique IDs. The ATT&CK identifiers below are the verifiable technique references that correspond to each stage of this lifecycle.
| Fraud Tactic | Observed behavior | ATT&CK Reference |
|---|---|---|
| Initial Access | Unsolicited or wrong-number SMS (smishing) | T1660 Phishing |
| Resource Development | Disposable phone numbers, fabricated personas | T1585 Establish Accounts, T1583 Acquire Infrastructure |
| Initial Access | Grooming, love-bombing, stolen-photo impersonation | T1656 Impersonation |
| Execution | Urgency, isolation, DARVO, coaching | T1656 Impersonation (partial) |
| Monetization | Crypto, gift-card, and wire deposit instructions | T1657 Financial Theft |
| Monetization | Cash-out and laundering of extracted funds | T1657 Financial Theft |
Conclusion
Link-based defenses have nothing to grip here, so the operators keep it that way: no URLs, one number per victim, low volume, and a fast migration to encrypted apps. Their weakness is repetition. The same scripts, the same Texas area codes, and the same grammatical tells recur across numbers that are otherwise disposable, and that repetition is what turns a hundred anonymous burners into one traceable operation. The trend to watch is the drift toward obscure encrypted messengers like Zangi, a move to stay ahead of monitoring that will only continue as the mainstream apps get harder to hide in.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.