How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped registration dates into its own WHOIS records. For roughly six months in 2025, the registrant organization field on its domains did not contain a company name. Instead, it held a batch code: r0514 for a set registered on 14 May, 304 for 4 March, r02222 for 22 February. Each code covers a run of sequentially named domains bought on a single day. In effect, the operator labelled its own inventory in public.
That fingerprint is now dead. It declined through the second half of 2025 and reached zero by the fourth quarter. Since then, the same kit has registered domains behind null or privacy-redacted WHOIS. This post examines what the fingerprint showed while it lasted, what replaced it, and the URL-path grammar that survived both.
Key Takeaways
- The registrant organization field on this kit's 2025 domains encodes the registration date.
r0514maps to 14 May,304to 4 March. Each code covers a same-day batch of sequentially labelled domains. - The fingerprint has a hard expiry. It peaked at 26.3 percent of the registration cohort in Q1 2025, declined through Q2 and Q3, and hit zero in Q4 2025. Detection logic built on it will silently stop matching.
- The kit routes by URL path using two separate vocabularies: bare country and agency codes (
/us,/ca,/uk,/il,/dmv,/rmv) for geography, and funnel-stage markers (/i,/info,/pay,/notice,/security) for position in the lure. Matching only one vocabulary misses half the fleet. - The brand sits in one of two positions, never as a standalone registrable domain. In the larger family it is a sub-label, so
usps[.]com-abcd[.]xinis the domaincom-abcd[.]xinwearinguspsas a prefix. In the batch-coded family the token is folded into the apex label itself, as inflhsmvwb[.]win. More than 40 distinct brand tokens appear across toll, parcel and government verticals. - Landing pages are scraped copies of the real government service, including canonical tags and site-verification tokens. Page content alone cannot separate the clone from the original.
Background
Public reporting has tracked a China-based smishing ecosystem since 2023 under several names, including the actor label "Smishing Triad" and the phishing-as-a-service kits "Lighthouse" and "Darcula". Resecurity first named the actor in 2023 research on USPS-themed data theft. In October 2025, Palo Alto Networks Unit 42 linked the operation to more than 194,000 malicious domains and noted that over two-thirds were registered through a single registrar, Dominet (HK) Limited. Google filed a civil suit in the Southern District of New York in November 2025 against 25 unnamed defendants. The suit alleged that the Lighthouse kit shipped more than 600 phishing templates covering over 400 brands, generated roughly 200,000 domains in a 20-day window, and reached more than a million victims across 120 countries.
Bitdefender Labs separately measured a global fake toll and traffic-fine wave it calls Operation Road Trap between December 2025 and April 2026. It counted more than 79,000 fraudulent messages across 40 campaign variants in at least a dozen countries. Bitdefender did not attribute that activity to a named actor. Its published samples use the same demoted-brand host shape and country-code path segments described below. This is notable because the two bodies of work have not been publicly connected.
Cheap and novelty gTLDs. Registries price TLDs such as .xin, .win, .top, .vip, .world, .cfd and .bond at a dollar or two a year, sometimes near zero for a promotional first year, to build volume. Several conduct little fraud screening at registration. An operation that burns thousands of domains every few days needs bulk, disposable registration without identity checks.
The demoted-brand host shape. In usps[.]com-abcd[.]xin, the registrable domain is com-abcd[.]xin, while usps is only a sub-label. On a phone's address bar, a reader gets as far as "usps.com" and stops. The trick is designed for mobile screens, where the rest of the string scrolls out of view.
The userinfo trick. In hxxps://www[.]ups[.]com@evil[.]tld/, everything before the @ is the RFC 3986 userinfo component, a largely obsolete credential slot. The browser connects to evil[.]tld. The brand string is only decoration.
Geo and user-agent cloaking. The lander fingerprints the visitor's IP and user agent. It serves a placeholder or an error to datacenter ranges, VPN exits and known scanner ASNs, while serving the real harvesting page only to in-country mobile traffic. For researchers, the practical consequence is that an empty fetch proves nothing.
Card-to-wallet provisioning. Google's complaint describes the cash-out process. The kit harvests the card number, expiry, CVV and a one-time passcode together. It relays the passcode in real time to enroll the stolen card into an attacker-controlled Apple Pay or Google Wallet, then holds the token before use so provisioning settles past issuer velocity checks. Independent reporting from Krebs on Security and Kaspersky describes the same pattern and its NFC relay cash-out.
Discovery and Infrastructure
We began tracking this kit after a parcel lure in October 2024. Since then, our tracking has covered six impersonation arms: US toll agencies, the IRS and state tax boards, state DMV and revenue departments, postal and parcel carriers across four countries, UK government services, and most recently the Israel Police traffic-fine service. Across the corpus, we have examined thousands of messages containing the kit's signature evasion instruction. It tells the recipient to reply "Y", close the message and reopen it so the link becomes tappable.
The infrastructure has two tiers. Brand-labelled frontends carry the lure, while a second tier of gibberish-labelled hosts operates as redirectors and payment endpoints. Both tiers register through the same small set of accredited registrars: Dominet (HK) Limited, Aceville Pte. Ltd., gname.com, NiceNIC International, Eranet International, Namemart, Alibaba Cloud (HiChina) and Xin Net. These are legitimate businesses with low-friction, API-driven bulk-registration models aimed at resellers and high-volume buyers. That model serves brand-protection firms and abusive registrants alike. The concentration described here shows where bulk registration is operationally easiest. It is not a finding about the registrars themselves.
How It Works
A recipient receives a text claiming a small, specific debt with a short deadline: an unpaid toll, a traffic fine, a customs charge on a held parcel, or a tax refund waiting to be claimed. The amount is usually under twenty units of local currency, low enough that a recipient may pay without thinking. The message includes a link on a domain registered hours or days earlier.
The link resolves to a copy of the real agency's payment page. In the Israel arm, we fetched one of these pages live and found a scraped mirror of the genuine Israel Police traffic-fine service on gov.il. It retained the real page's canonical URL, OpenGraph metadata and Google site-verification token unchanged. The page collects card details, followed by a one-time passcode. According to the public complaint, that passcode completes enrollment of the card into a wallet controlled by the operator.
Two arms of the same fleet, registered on the same day, show the cloaking in practice. One served the full clone to our fetch. A second returned a 98-byte plain-text maintenance notice, while a third returned a server error. All three had been registered that morning.
Sample Lures
We replaced all recipient identifiers with placeholders. Every URL is defanged.
Israel Police traffic fine (Hebrew, translated below). Delivered from a spoofed Indian mobile number.
הודעה ממשטרת התנועה בישראל
יקירתי:
יש לך דו"ח תנועה באיחור.
סטטוס: ממתין לתשלום
אנא לחץ על הקישור הבא כדי לשלם את הקנס.
hxxps://gov-update[.]cfd/il?tjwaq=8XI8irZ5
אנא נקט בפעולה המתאימה תוך 24 שעות מקבלת הודעה זו; אחרת,
התיק יועבר לבית המשפט לתעבורה המקומי.
Translation: "Notice from the Israel Traffic Police. Dear [recipient], you have an overdue traffic report. Status: awaiting payment. Please click the following link to pay the fine. Take appropriate action within 24 hours of receiving this notice; otherwise the file will be transferred to the local traffic court."
US toll violation (E-ZPass). The evasion instruction is the kit's most durable content marker.
E-ZPass - Toll Violation Notice: This is an official notice regarding an
outstanding toll balance on your E-ZPass account. To avoid incurring
additional late fees, please ensure payment is made within the next 12 hours.
hxxps://e-zpass[.]com-etcsk[.]win/us
(Please reply "Y", then exit the text and reopen to activate the link, or
copy the link to open in your Safari browser)
IRS refund. The real agency domain is demoted to a sub-label of an operator apex.
Internal Revenue Service (IRS) You are eligible to receive a $1,400 Economic
Impact Payment. Please provide your accurate personal information. We will
deposit the amount into your bank account or mail a paper check within 1 to 2
business days.
hxxps://www[.]irs[.]gov-safety[.]com
(Please reply with 'Y,' then exit the text message. Open it again, click the
link, or copy it into your Safari browser)
USPS redelivery.
USPS Delivery Team: Our staff was unable to deliver your package to
[recipient address]. Please confirm your address to reschedule delivery.
hxxps://usps[.]com-lz[.]xin/mum
(Please reply with a Y, then exit the text message and open it again to
activate the link, or copy the link into your Safari browser and open it)
UK parking penalty.
GOV.UK: You have an outstanding Parking Penalty Notice. PCN Notice number:
[reference]. Fine amount: £20. This is a final notice - failure to pay may
result in a county court judgment and a negative impact on your credit rating.
Pay now: hxxps://www[.]govuk-parkingfines[.]xin/gov
(Please reply Y, then exit the SMS, reopen the SMS activation link, or copy
the link to open in Safari)
Technical Analysis
The Registrant Organization Is a Batch Date
The WHOIS registrant organization field accepts free text. Under post-GDPR policy, most registrars redact it by default, so it is usually uninformative. This operator left it populated through most of 2025. The field did not contain a company name.
Two patterns run in parallel. The first is a date code: a short numeric or alphanumeric string that tracks the day the batch was bought. The second is keyboard mash, a fixed nonsense string reused across a run. Analytically, both behave the same way. Each value covers a set of domains registered within a day or two of each other, with sequential labels drawn from one vocabulary.
| Registrant org | Domains | Created | Example members |
|---|---|---|---|
11 |
256 | 2025-02-27 to 2025-05-30 | com-ticketav[.]xin, com-ticketax[.]xin, com-ticketcc[.]xin |
222 |
129 | 2025-02-19 to 2025-03-06 | com-ticketeqa[.]xin, com-ticketeqb[.]xin, com-ticketeqd[.]xin |
304 |
64 | 2025-03-04 to 2025-03-05 | com-ticketeia[.]xin, com-ticketeib[.]xin, com-ticketeic[.]xin |
r0339 |
63 | 2025-03-09 | com-ticketeda[.]xin, com-ticketedd[.]xin, com-ticketede[.]xin |
r02222 |
59 | 2025-02-22 | com-fastrakrb[.]xin, com-fastrakrc[.]xin, com-fastrakrd[.]xin |
r0514 |
49 | 2025-05-14 to 2025-05-15 | flhsmvwb[.]win, flhsmvwc[.]win, flhsmvwm[.]win |
afsas |
166 | 2025-03-07 to 2025-04-17 | abhfo[.]xin, abvwc[.]xin, agtds[.]xin |
asdda |
103 | 2025-02-24 to 2025-03-24 | com-tollbillmne[.]xin, com-tollbillmnq[.]xin, com-tollbillmsa[.]xin |
q11 |
60 | 2025-02-20 to 2025-02-24 | com-fastrakia[.]xin, com-fastrakid[.]xin, com-fastrakie[.]xin |
21 |
14 | 2025-07-19 to 2025-08-05 | govuk-subsidy-apply[.]fashion, govuk-subsidy-apply[.]fit, govuk-subsidy-apply[.]ink |
rhrtghfhjft |
8 | 2025-05-12 to 2025-05-15 | engdwpcq[.]icu, engdwpgr[.]icu, engdwphe[.]icu |
Where the code is readable, the date mapping is exact. r0514 covers domains created 14 and 15 May. 304 covers 4 and 5 March. r02222 covers 22 February. The same tooling produces every arm. The lure vocabulary changes from tollbill to fastrak to ticket to engdwp to govuk-subsidy-apply, but the batching behaviour remains the same.
The Fingerprint Has an Expiry Date
Anyone building on this fingerprint needs to account for its expiry. Measured by quarter of WHOIS creation, the share of the registration cohort carrying a junk or date-coded organization value was:
| Quarter | Share carrying the fingerprint |
|---|---|
| Q4 2024 | 0% |
| Q1 2025 | 26.3% |
| Q2 2025 | 11.4% |
| Q3 2025 | 5.5% |
| Q4 2025 | 0% |
| Q1 to Q3 2026 | 0% |
From Q4 2025 onward, the cohort contains only null or privacy-redacted organization values. A rule keyed on the organization string does not fail loudly when this happens. It continues to run but stops matching, the worst failure mode for a detection. Anything built on this signal needs three fallbacks that survived the change: the registrar cohort, the naming grammar and the same-day registration-to-delivery gap.
Sequential Batching Is Visible in the Labels
Labels increment within each batch. Beyond the sets named above, we confirmed further runs: com-etcw{a-h} across .win and .xin (46 domains), org-txtagstorefrontqa{a-e} across .xin and .world (43), com-etcc{a-e} (41), com-etcx{a-d} (38), com-xaaaq{a-f} across .vip and .top (35), thetollroads-tollevasionz{a-c} (33), and four separate com-tollbill runs of 28 each. The label suffix advances through the alphabet, while the TLD sometimes alternates within a single batch. This suggests that registration is scripted against more than one TLD at a time.
The Brand Is Always a Sub-Label
Across the registration cohort, more than 40 distinct brand tokens appear as the immediate sub-label on operator apexes. The registrable domain never contains the brand.
| Brand token | Hosts observed | Vertical |
|---|---|---|
| e-zpass | 2,973 | Toll |
| txtag | 2,961 | Toll |
| e-zpassny | 2,259 | Toll |
| usps | 2,122 | Parcel |
| ezpass | 1,853 | Toll |
| sunpass | 1,627 | Toll |
| ezdrivema | 1,582 | Toll |
| getipass | 737 | Toll |
| ohioturnpike | 724 | Toll |
| mypeachpass | 657 | Toll |
| bayareafastrak | 519 | Toll |
| thetollroads | 449 | Toll |
| fedex | 379 | Parcel |
| mndot | 347 | Government |
| evrimail | 334 | Parcel |
| ncquickpass | 278 | Toll |
| driveezmd | 250 | Toll |
| vdot | 179 | Government |
| puroletor | 176 | Parcel |
| royalmail | 42 | Parcel |
| dpd | 33 | Parcel |
The puroletor token deliberately misspells the Canadian carrier Purolator and was registered alongside correctly spelled variants. Generic filler labels (secure, www, track, tools) recur when no brand is present.
Two Path Vocabularies, Not One
The kit encodes routing in the URL path using two distinct vocabularies that can easily be conflated.
| Type | Path | Observed |
|---|---|---|
| Country or agency | /us |
1,506 |
| Funnel stage | /i |
321 |
| Funnel stage | /info |
289 |
| Funnel stage | /pay |
232 |
| Country or agency | /ca |
177 |
| Funnel stage | /I (case variant) |
133 |
| Country or agency | /uk |
63 |
| Funnel stage | /security/page.html |
59 |
| Country or agency | /ma (Massachusetts) |
16 |
| Funnel stage | /usvip |
15 |
| Funnel stage | /Pendingdelivery |
14 |
| Country or agency | /es |
7 |
| Country or agency | /dmv, /gov |
5, 5 |
| Country or agency | /rmv |
4 |
| Country or agency | /il (Israel) |
3 |
| Country or agency | /mum |
2 |
The country and agency codes select geography and persist through domain rotation. The funnel-stage markers identify the visitor's position in the lure: /i and /info for the notice, /pay for the card form, /security for an account-verification template, and /Pendingdelivery for the parcel variant. A sweep keyed only on two-letter country codes misses the entire funnel-stage population. The reverse is equally true. The /il Israel arm, with three observed paths, is the newest and smallest.
What Changed, and When
The first lure in our corpus is a parcel message from October 2024. The largest registration burst runs from February through June 2025, when the WHOIS organization fingerprint also carries most of the analytical weight. During the second half of 2025, that fingerprint declines to nothing as registration moves behind privacy redaction. In 2026, the kit reappears on newer cheap gTLDs including .bond, .life, .qpon and .forum. These domains have no organization value at all, and the registration-to-delivery gap is measured in hours. The three Israel domains were registered and used to send on the same day.
Detection Observations
The following behavioural properties distinguish the campaign's traffic from legitimate agency messaging.
The sending number has no relationship to the target country. Israeli recipients received messages from Indian and Uruguayan mobile numbers. US and UK arms have used numbers from the UK, Philippines, Democratic Republic of Congo, Benin and UAE. A real toll authority or tax office sends from in-country infrastructure or a registered alphanumeric sender ID. Sender-country heuristics keyed to the recipient's market will not fire on this because the mismatch is total, not subtle.
The registrable domain and the displayed brand never match. Any host with a recognizable agency or carrier name as a sub-label on an unrelated registrable domain is worth treating as hostile based on its shape alone. This pattern holds across every arm and both registration eras.
Registration age is measured in hours. In the 2026 arms, WHOIS creation and first observed delivery occur on the same calendar day. Age-based reputation has no time to accumulate. That is the design intent.
Page content is not a discriminator. The landing pages are byte-level scrapes of the genuine service, including canonical URLs and verification tokens belonging to the real agency. Any check based on page content will read the clone as legitimate. Judgement must instead rest on the host, registration and delivery path.
An empty response is not exoneration. Because of cloaking, a domain that returns a maintenance stub or server error to an automated fetch may simultaneously serve a full credential-harvest page to in-country mobile traffic. A sibling domain registered in the same batch served the real page while two others did not.
Indicators of Compromise
Representative subset, defanged. Full sets are larger than shown.
Domains
| Domain | Arm |
|---|---|
| gov-warning[.]cfd | Israel traffic fine |
| gov-update[.]cfd | Israel traffic fine |
| traffic-fines[.]net | Israel traffic fine |
| flhsmvwb[.]win | Florida DMV |
| georgia-govlua[.]icu | Georgia government |
| dmv-govlac[.]icu | State DMV |
| tn-govqdf[.]win | Tennessee government |
| gov-mdotr[.]icu | Michigan DOT |
| alabama-govlx[.]today | Alabama government |
| canada-postsecanadash[.]top | Canada Post |
| cagov-roh[.]net | California tax board |
| auth-irsbill5050[.]com | IRS |
| aid-receives[.]com | Tax refund |
| dwpend[.]top | UK benefits |
| dwppb[.]top | UK benefits |
| ... (representative subset; 750+ verified-malicious domains) |
Hosts
| Host | Arm |
|---|---|
| ny[.]gov-cwaw[.]bond | New York tax |
| idot[.]com-skln[.]com | Illinois DOT |
| mn[.]com-mnf[.]com | Minnesota government |
| tn[.]org-bht[.]qpon | Tennessee government |
| wa[.]org-wds[.]forum | Washington government |
Sending numbers
| Number | Arm |
|---|---|
| +91 9062539520 | Israel traffic fine |
| +91 7692856907 | Israel traffic fine |
| +598 95974933 | Israel trip invoice |
| +1 5103422414 | New York tax |
MITRE Fight Fraud Framework Mapping
This mapping follows the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 primarily covers post-access fraud behaviour, so a pre-access lure operation maps only partially. The final two rows cover monetization stages documented in public reporting rather than observed by us, and are marked accordingly.
| F3 Tactic | Technique | ID |
|---|---|---|
| Reconnaissance | Phishing for Information | T1598 |
| Resource Development | Acquire Infrastructure: Domains | T1583.001 |
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Initial Access | Phishing | T1660 |
| Initial Access | Impersonate Official | F1032 |
| Stealth | Phone Number Spoofing | F1040 |
| Stealth | Geolocation Spoofing | F1030 |
| Execution | Abuse SMS verification (per public reporting) | F1003 |
| Monetization | Electronic Funds Transfer (per public reporting) | F1025 |
Conclusion
The registrant organization field was not intended to carry operational meaning, yet for most of 2025 this operator used it as a production log. That signal is now gone. The remaining properties are less convenient but more durable: a registrar cohort that public research has independently tied to more than two-thirds of 194,000 domains, a host grammar that either demotes the brand below the registrable name or folds it into the apex label, a two-vocabulary path scheme, and a registration-to-delivery gap now measured in hours rather than days.
The Israel arm is the newest and smallest instance: three domains registered and burned on a single day in September 2026. Ynet and the National Insurance Institute (Bituach Leumi) have reported a parallel wave impersonating Bituach Leumi, Israel Post, Highway 6 and the Israel Police, so the market is not a new target. The new finding is the fingerprint connecting it to the same kit behind the US toll and UK benefits arms. Bitdefender's Operation Road Trap tracking covers a dozen countries without naming an actor, and its published samples contain the same host shape and country-code paths. The two bodies of work describe infrastructure with matching structure.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.
Rented Storefronts: A Fake-Store Franchise on Facebook Ads
Across 2026 we mapped 100+ fraudulent storefronts fronted by disposable Facebook advertisers, increasingly hosted as tenants on legitimate builder platforms.