
Called Chinese-speaking phishing group Postal Furious Group-IB said it was linked to a new SMS campaign targeting users in the UAE posing as a postal service and toll operator.
This scam involves sending users fake text messages asking them to pay for a vehicle transfer to avoid additional fines. The message also contains a shortened URL to hide the actual phishing link.
Clicking on this link leads unsuspecting recipients to a fake landing page designed to obtain payment credentials and personal data. This campaign is scheduled to run as of April 15, 2023.

“Text URLs lead to fake branded payment pages requesting personal information such as name, address and credit card information,” Group-IB said. “The phishing page uses the official name and logo of a spoofed postal service provider.”
The exact scale of the attack is unknown at this time. What is known is that the text messages were sent from a phone number registered in Malaysia and Thailand and via an email address via the Apple iMessage service.
To avoid detection, the phishing links are geofenced, making the pages accessible only from UAE-based IP addresses. Attackers have also been observed registering new phishing domains every day to increase their reach.
A second nearly identical campaign, observed on April 29, 2023, mimicked the UAE postal operator, according to a Singapore-based cybersecurity firm.
🔐 Mastering API Security: Understanding Your True Attack Surface
Uncover untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join us for an insightful webinar!
join the session
This smishing activity marks an expansion of efforts since at least 2021, when threat actors began targeting users in the Asia-Pacific region. Group-IB said the PostalFurious operation demonstrated “the transnational nature of organized cybercrime.”
To avoid falling prey to such scams, it is advisable to develop a habit of clicking cautiously when it comes to links and attachments, keep your software up to date, and ensure a strong digital hygiene routine. To do.
The development follows a similar postal-themed phishing campaign called Operation Red Deer that targeted various organizations in Israel to distribute a remote-access Trojan called AsyncRAT. This attack is limited to an attacker codenamed “Aggah”.