Uptime Hamster: 43d 0h 45mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21

Group-IB Threat Intelligence: Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics.

Fecha
29 Apr 2026
Actor
x-cti
Tipo
Phishing
Pais
United States
Sector
Media
Confianza
high
58
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

0IOCs
1TTPs
x-ctiActor
United StatesPais
Executive Summary
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.

Key Points

  • Tweet original en X
  • Perfil de @GroupIB_TI

Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics.

Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.


Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics. Despite using different lures, reward points versus failed parcel delivery, both campaigns share identical backend infrastructure, IP filtering, and geofencing controls, confirming they are not independent operations but branches of a centralized #smishing framework.

Group-IB Threat Intelligence: Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics.

Group-IB Threat Intelligence: Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics.


Referencias

Diamond Model

Adversary
x-cti
Ver perfil →
Victim
Group-IB Threat Intelligence: Since January 2025, Group-IB has tracked over 2,500 #phishing domains tied to a single #PhaaS ecosystem known as the "Phoenix System" (不死鳥系統), which has targeted more than 70 organizations across financial services, telecom, and logistics.
United States
Capability
Phishing
1 TTPs MITRE
Infrastructure
Sin infraestructura confirmada

Referencias y enlaces

→ Perfil del actor x-cti en el blog → Ver x-cti en IntelTracker → URL IntelTracker: nitter.net→ URL IntelTracker: x.com → Fuente OSINT: nitter.net→ Fuente OSINT: x.com → Buscar x-cti en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes