It started with a text that wanted me to review my taxes.
annualreview-taxaccount.com
The domain looked almost boring: annualreview-taxaccount.com. No drama in the branding. No obvious typosquat of canada.ca. Just enough bureaucratic blandness to pass a glance on a phone screen. Most people delete these. I pulled the thread.
Behind that SMS was a real-time adversary-in-the-middle kit impersonating CRA My Account. It sat on a bulletproof farm in Fremont that was also carrying valid Microsoft and GitHub certificates on adjacent IPs. A few weeks later, on a different channel, I was inside Facebook "Meta Verified" phishing infrastructure. One bot in that cluster had already taken roughly three thousand credentials.
SMS tax scare. Blue-tick flattery. Same machine under both. This is what the kits look like when you stop treating smishing and social phishing as different problems.
What smishing actually is
Smishing is phishing over SMS, RCS, or iMessage. The goals match email phishing: click, call, install, or hand over credentials and codes. The channel advantages are structural. Texts feel personal. Mobile browsers truncate URLs. Carrier filtering is weaker and less consistent than email authentication (SPF, DKIM, DMARC). People who would never open a cold email will tap a "package held" or "account suspended" text without thinking.
The CRA lure I got was textbook channel choice. Tax anxiety is seasonal and universal in Canada. CRA does not ask taxpayers to provide personal or financial information through an unsolicited text link like this. Scammers count on most recipients not knowing that.
Case 1 - The CRA text and the AiTM kit
Domain intelligence came first. annualreview-taxaccount.com had been registered about four days earlier through NiceNIC in Hong Kong. SSL certificate issued six minutes after registration. DNS on Tencent's DNSPod. No MX records. The name existed as a trap and nothing else.
SMS lure
Smishing text links victim to annualreview-taxaccount.com
XOR loader
Obfuscated JS (key 156) + Client Hints fingerprint. Bots get 404.
CRA clone
Pixel-level Government of Canada portal. WET toolkit CSS, real branding.
Credential capture
JSON POST to update endpoint. Fields staged for the operator panel.
Operator panel
Real-time relay. Tests creds on actual CRA. Pushes MFA capture live.
Victim held
"Please wait" screen while the operator works the real account behind it.
The landing page served almost nothing visible: a CSS spinner and XOR-obfuscated JavaScript (key 156) with randomized variable names. The decoded loader fetched a second stage only for real browsers holding a valid PHP session and Client Hints fingerprints. Bots and curl got a 404. Built to hate scanners.
Once the JavaScript ran, the page rendered a pixel-level CRA My Account clone. Government of Canada branding. WET toolkit CSS. The kind of visual fidelity that makes a victim's gut say "this is official."
Credentials did not sit in a static database for later. They posted as JSON to an update endpoint, then the victim landed on a "please wait" screen. Behind that spinner, an operator was testing the stolen credentials against the real CRA site in real time. If CRA challenged for MFA, the operator pushed the victim into a second step and harvested the code live. Full two-factor bypass with a human in the loop.
That distinction matters. A static harvester is a leak. A live relay is an account takeover pipeline.
NiceNIC / HK
The /24 behind the lure
The capture host resolved to 130.12.44.213, sitting under a US Virgin Islands shell calling itself ZhouyiSat Communications, physically colocated in Hurricane Electric's FMT2 facility in Fremont, California. Abuse contact: a Russian dead-end mailbox. Support portal on a Chinese cloud brand fronting Yandex Cloud.
Scanning the rest of the /24 made the CRA site look like a tenant on a shared floor.
nginx + PHP
cert, full chain
cert, full chain
US node / REG.RU
FASTPANEL
Those Microsoft and GitHub certificates were full production chains. That is consistent with Evilginx-style reverse-proxy infrastructure: terminate TLS as the real brand, relay to the real service, steal session material in flight. Same technique class as the CRA kit, aimed at enterprise accounts, on the same iron.
The stack was laundered across jurisdictions on purpose.
registrar
China DNS
shell co.
dead-end
Cloud front
physical
I filed abuse with Hurricane Electric and the registrar, published a technical thread, and wrote a poisoner that floods the kit's intake with realistic-looking Canadian credentials so harvested data becomes unreliable. Active disruption described here was conducted only where authorization and applicable legal authority permitted; details that would materially enable unauthorized access are omitted. If you received that text: do not click, forward the message to 7726 where your carrier supports it, and if you already typed anything, freeze credit and contact CRA directly through official channels. Never through the link.
Case 2 - Meta blue ticks and session theft
The Facebook work arrived on a different vector and a different scale. Public reporting from Hunt.io and Unit 42 documents related ClickFix tradecraft and Meta-focused session-theft activity. The specific campaign described here was publicly documented by late 2025, with related ClickFix techniques observed earlier. Internally, or in some operator-facing contexts, similar lures may be referred to as “Bluetick.” Lure themes: free verification badge, suspended-page recovery, "your business was selected for Creator Verify." Targets skew toward page admins, creators, and monetized accounts. Those public tallies run past a hundred hostnames and more than a hundred distinct pages in the attack chain.
I worked live kits in that ecosystem through the first half of 2026. The picture from inside the infrastructure, rather than from the lure, looks like this.
How the Facebook kits actually steal
Early Vercel-hosted variants did something clever with Facebook's own crawler. A normal browser hitting the deployment received a large Next.js decoy, often a furniture or generic business template with no obvious phishing content. Facebook's link preview bot (facebookexternalhit) received a 307 redirect to a route that returned almost nothing except Open Graph tags: official-looking Meta logo, title along the lines of "Official Notice from Facebook," description copy about a permanent creator badge. Paste any path on the deployment into Facebook and the preview card looked institutional. The human who clicked through got a different path entirely.
Capture flow was multi-stage. Identity and page details first. Password second. Two-factor codes third. The more dangerous variants preferred session material, Facebook c_user and xs cookie pairs, over passwords alone. A stolen live session bypasses 2FA completely because the session is already authenticated. Passwords and backup codes were collected as fallback.
Exfiltration clustered on two patterns:
- Telegram bots. Each victim step forwarded as a message into an operator chat. When the bot token was recoverable, the entire harvest pipeline became readable — and usable for authorized victim-rescue disruption.
- Serverless form backends. Endpoints on services like submit-form.com / Formspark and similar "paste a form, get a POST URL" products. Frontends rotate daily. Collection backends stick around longer, which matches the sticky collection backends Hunt.io told defenders to track.
Round 1: recover the bot, notify the victims
One Vercel-era kit shipped its Telegram bot token in client-side configuration. That is a sloppy mistake. It is also how victim rescue scales.
With a live token you do not need to guess who got hit. You read the operator's own intake channel. Over roughly four months, one recovered bot in this cluster had accumulated about ~3,400 Facebook credential/session records captured in that intake. Canadian cases were routed through the Canadian Anti-Fraud Centre. The bot was renamed, the channel was burned from the operator's side, and where notification channels were available, affected users could be warned and advised to rotate credentials and sessions before the records aged into secondary fraud.
A clean takedown with zero outreach is a press release. A recovered exfil channel is how thousands of humans get a warning path. That is the point of the work.
Round 2: the operators read the post-mortem
They adapted quickly after the writeup landed.
- Bot token in browser bundle
- Vercel static / Next decoy
catthe config, recover the chat
- Next.js Server Actions
- Env vars on Render / peers
- Laravel + ngrok / CF tunnels
Successor kits moved off plaintext client config onto Next.js Server Actions, with bot tokens held in server-side environment variables on Render and similar hosts. From the public internet you can still fingerprint the lure, the anti-analysis tooling, and the multi-stage UX. You cannot cat the token out of a browser bundle anymore. Parallel variants used Laravel backends fronted by ephemeral tunnels (ngrok, Cloudflare quick tunnels), which come up and down with the operator's laptop lid.
Git history still betrayed kit developers who committed fallback defaults and coursework credentials into public repositories. Language artifacts in helper files, Vietnamese comments and i18n bundles spanning a dozen-plus languages of Meta UI chrome, tied throwaway deploy accounts back into a common tooling culture even when the GitHub identities were week-old empties hosting dozens of deploy-* repos each.
Hosting rotated across Vercel, Render, Netlify, Wasmer, Surge, GitHub Pages, Cloudflare Pages, Neocities. The durable signals were page titles, template structure, collection backends, and exfil shape. The domain of the week was noise.
Case 3 - Shorteners, content farms, and burner rotation
By August 2026 a related Meta/Instagram credential network was running a cleaner separation of concerns.
Vercel actioned the burner fleet hard once evidenced. Forty-eight hosts returned legal-block responses. The shortener layer and dispatcher stayed up longer. That is the architectural lesson. If you only kill the last hop, the operator respawns capture nodes behind the same rotation logic by afternoon. Disruption has to climb the stack: burners, dispatcher, shortener, content farm, registrar, CDN account, brand abuse desk, browser blocklists. In parallel. Not one ticket at a time.
Native-language comments in dispatcher code and corporate WHOIS on the shortener family pointed at a Vietnamese-speaking operation running behind a US-registered LLC shell. Same region as a lot of the Bluetick tooling. Read that as density of talent and infrastructure. It is not a courtroom-ready claim of one single gang.
One doctrine across three channels
SMS tax scare. Facebook blue-tick flattery. Instagram password-reset shortlink. Different inboxes. Same underlying machine.
| Layer | What to take |
|---|---|
| Delivery | SMS, social graph, SEO+shortlink. Costume layer. |
| Lure | Anxiety (tax, suspension) or aspiration (badge, unlock) |
| Kit | Multi-stage capture, anti-bot gates, often live relay or session theft |
| Host | Bulletproof colo or disposable PaaS burners behind rotation |
| Exfil | Telegram bots or serverless form backends. This is where the real mass sits. |
| Cash-out | Account takeover, resale, ads fraud, secondary phishing as the victim |
The working playbook that came out of these engagements:
Enumerate the kit, ahead of the domain
Domains die in days. Bundle strings, page titles, dispatcher JavaScript, and exfil shapes survive rotation.
Hunt the exfil channel first
A recovered Telegram bot token or a sticky form-backend URL is worth more than twenty burner takedowns. That is how you see victims.
Victims first, infrastructure second
Notify people. Route Canadians through CAFC. Then burn the hosts. That order matters.
Where authorized, poison when you cannot seize
Where authorized, poisoning can degrade an intake pipeline when seizure is not available. If the intake is open and the token is locked down, realistic fakes can make the operator's database a liability. Mark canaries privately.
Abuse in parallel
Host platform, CDN, registrar, impersonated brand, Google Safe Browsing, APWG, national CERT. Serial reporting is how campaigns outlive your attention span.
Attribute when OPSEC fails, then hand it off
Student emails in git history, payment rails, corporate shells. Publish techniques. Pass identities to people with warrants.
Assume your writeup is their sprint backlog
Round 1 plaintext tokens became Round 2 server-side env vars. Public research gets mocked in operator bot bios. The correct response is still to move anyway.
What defenders and platforms should change
CRA, banks, and major platforms do not cold-text you magic links to "review" or "verify" under threat of loss. Open the app or type the official domain yourself. Forward suspected spam texts to 7726 where your carrier supports it, and report fraud or cybercrime to the Canadian Anti-Fraud Centre. If you typed a password into a fake page, rotate it from a clean device and kill active sessions. If it was Facebook, revoke sessions and review connected apps immediately.
AiTM kits with valid brand certificates on bulletproof IP space mean MFA alone is incomplete. Prefer phishing-resistant authenticators (passkeys, hardware-bound keys) over SMS or approve/deny prompts that a live relay can simply forward. Monitor for reverse-proxy infrastructure patterns in your threat intel feeds. Lookalike domains are only one slice of the problem.
Faster 451s when evidence is tight. The gap is correlation: forty-eight burners behind one dispatcher should land as one case instead of forty-eight tickets. Share dispatcher and shortener fingerprints across trust-and-safety teams the way browser vendors share Safe Browsing signals.
Crawler-specific cloaking that serves institutional OG cards to facebookexternalhit while serving decoys to users is a solved detection class if you compare the two responses on every reported URL. Session-cookie theft should trigger the same severity path as password breaches. Blue-tick and page-appeal lure language is stable enough to be a proactive classifier. Waiting on a reactive abuse queue is too slow.
The CRA campaign's expensive hop was the text itself. A2P and traffic-pumping controls catch some of this. They miss targeted, low-volume, high-believability sends. Cross-carrier threat exchange on message body templates and landing domains still lags email by a decade.
Why this work
I build security and intelligence systems for a living, including SCAFU. These engagements were concrete operations against live theft pipelines aimed at real people: Canadian taxpayers staring at a fake CRA spinner while someone tested their password, and Facebook page owners who thought Meta had finally given them a badge.
The through-line to everything else I ship is evidence-grade truth. Kits leave artifacts. Operators reuse strings. Exfil channels concentrate risk. Document those things carefully enough to survive adversarial scrutiny and you can move platforms, warn victims, and occasionally put a name and a payment rail in front of someone who can do more than write a blog post.
Smishing is the SMS door into the same credential economy that runs on blue-tick lures and shortlink laundering. Treat the channel as a detail. Hunt the kit. Recover the exfil when authorized. Tell the victims. Burn what is left. Then assume they are already building the next version.
Portions of the CRA case were first published as a technical thread in March 2026. Public campaign context on related ClickFix tradecraft and Meta-focused session theft draws on reporting by Hunt.io and Unit 42 alongside direct kit analysis. CRA scam-recognition guidance: canada.ca. Operational details that would help copycats or expose uninvolved third parties are withheld. Counsel-grade briefing: SCAFU Investigations.
← Back to Blog