← Back to Blog

It started with a text that wanted me to review my taxes.

Fig 0 The text that started it
CRA-Notice 11:42
Canada Revenue Agency: Your 2025 tax account requires annual review. Confirm your details within 24 hours to avoid hold on refunds.

annualreview-taxaccount.com
RECONSTRUCTED LURE · NOT A LIVE LINK
Reconstructed from the live lure pattern. Domain registered four days earlier. No MX. Trap only.

The domain looked almost boring: annualreview-taxaccount.com. No drama in the branding. No obvious typosquat of canada.ca. Just enough bureaucratic blandness to pass a glance on a phone screen. Most people delete these. I pulled the thread.

Behind that SMS was a real-time adversary-in-the-middle kit impersonating CRA My Account. It sat on a bulletproof farm in Fremont that was also carrying valid Microsoft and GitHub certificates on adjacent IPs. A few weeks later, on a different channel, I was inside Facebook "Meta Verified" phishing infrastructure. One bot in that cluster had already taken roughly three thousand credentials.

SMS tax scare. Blue-tick flattery. Same machine under both. This is what the kits look like when you stop treating smishing and social phishing as different problems.

What smishing actually is

Smishing is phishing over SMS, RCS, or iMessage. The goals match email phishing: click, call, install, or hand over credentials and codes. The channel advantages are structural. Texts feel personal. Mobile browsers truncate URLs. Carrier filtering is weaker and less consistent than email authentication (SPF, DKIM, DMARC). People who would never open a cold email will tap a "package held" or "account suspended" text without thinking.

The CRA lure I got was textbook channel choice. Tax anxiety is seasonal and universal in Canada. CRA does not ask taxpayers to provide personal or financial information through an unsolicited text link like this. Scammers count on most recipients not knowing that.

Case 1 - The CRA text and the AiTM kit

Domain intelligence came first. annualreview-taxaccount.com had been registered about four days earlier through NiceNIC in Hong Kong. SSL certificate issued six minutes after registration. DNS on Tencent's DNSPod. No MX records. The name existed as a trap and nothing else.

Fig A How the CRA kit actually works
1

SMS lure

Smishing text links victim to annualreview-taxaccount.com

2

XOR loader

Obfuscated JS (key 156) + Client Hints fingerprint. Bots get 404.

3

CRA clone

Pixel-level Government of Canada portal. WET toolkit CSS, real branding.

Credential capture

JSON POST to update endpoint. Fields staged for the operator panel.

Operator panel

Real-time relay. Tests creds on actual CRA. Pushes MFA capture live.

5

Victim held

"Please wait" screen while the operator works the real account behind it.

Static harvester = leak. Live relay = account takeover pipeline. The spinner is the tell.

The landing page served almost nothing visible: a CSS spinner and XOR-obfuscated JavaScript (key 156) with randomized variable names. The decoded loader fetched a second stage only for real browsers holding a valid PHP session and Client Hints fingerprints. Bots and curl got a 404. Built to hate scanners.

Once the JavaScript ran, the page rendered a pixel-level CRA My Account clone. Government of Canada branding. WET toolkit CSS. The kind of visual fidelity that makes a victim's gut say "this is official."

Credentials did not sit in a static database for later. They posted as JSON to an update endpoint, then the victim landed on a "please wait" screen. Behind that spinner, an operator was testing the stolen credentials against the real CRA site in real time. If CRA challenged for MFA, the operator pushed the victim into a second step and harvested the code live. Full two-factor bypass with a human in the loop.

That distinction matters. A static harvester is a leak. A live relay is an account takeover pipeline.

Fig D How fast they spun it up
T+0 min
Domain registered
NiceNIC / HK
T+6 min
SSL cert issued
T+5 hrs
BGP route announced
T+4 days
SMS campaign live
Four days from registration to inbox. No MX records at any point. Name existed as a trap only.

The /24 behind the lure

The capture host resolved to 130.12.44.213, sitting under a US Virgin Islands shell calling itself ZhouyiSat Communications, physically colocated in Hurricane Electric's FMT2 facility in Fremont, California. Abuse contact: a Russian dead-end mailbox. Support portal on a Chinese cloud brand fronting Yandex Cloud.

Scanning the rest of the /24 made the CRA site look like a tenant on a shared floor.

Fig B What else is on 130.12.44.0/24
.213
CRA phishing kit
nginx + PHP
Phishing
.204
Valid microsoft.com
cert, full chain
AiTM proxy
.210
Valid github.com
cert, full chain
AiTM proxy
.203
ShadowNet
US node / REG.RU
VPN / C2
.214/.215
*.max.ru stack
FASTPANEL
Infra
Microsoft and GitHub certs are production chains. Consistent with Evilginx-style reverse-proxy infrastructure on the same iron as the CRA kit.

Those Microsoft and GitHub certificates were full production chains. That is consistent with Evilginx-style reverse-proxy infrastructure: terminate TLS as the real brand, relay to the real service, steal session material in flight. Same technique class as the CRA kit, aimed at enterprise accounts, on the same iron.

The stack was laundered across jurisdictions on purpose.

Fig C Who is behind it (good luck serving one warrant)
NiceNIC
Hong Kong
registrar
DNSPod
Tencent
China DNS
ZhouyiSat
USVI
shell co.
Abuse MX
Russian
dead-end
62yun.co
Yandex
Cloud front
HE FMT2
Fremont, CA
physical
Six jurisdictions. One physical facility. No single warrant path kills the stack.

I filed abuse with Hurricane Electric and the registrar, published a technical thread, and wrote a poisoner that floods the kit's intake with realistic-looking Canadian credentials so harvested data becomes unreliable. Active disruption described here was conducted only where authorization and applicable legal authority permitted; details that would materially enable unauthorized access are omitted. If you received that text: do not click, forward the message to 7726 where your carrier supports it, and if you already typed anything, freeze credit and contact CRA directly through official channels. Never through the link.

Case 2 - Meta blue ticks and session theft

The Facebook work arrived on a different vector and a different scale. Public reporting from Hunt.io and Unit 42 documents related ClickFix tradecraft and Meta-focused session-theft activity. The specific campaign described here was publicly documented by late 2025, with related ClickFix techniques observed earlier. Internally, or in some operator-facing contexts, similar lures may be referred to as “Bluetick.” Lure themes: free verification badge, suspended-page recovery, "your business was selected for Creator Verify." Targets skew toward page admins, creators, and monetized accounts. Those public tallies run past a hundred hostnames and more than a hundred distinct pages in the attack chain.

I worked live kits in that ecosystem through the first half of 2026. The picture from inside the infrastructure, rather than from the lure, looks like this.

How the Facebook kits actually steal

Fig E Same URL. Two responses.
Normal browser
Next.js decoy
Furniture store or generic business template. No obvious phishing content. Looks like a real product site.
facebookexternalhit
307 → OG card only
Official-looking Meta logo. Title: "Official Notice from Facebook." Copy about a permanent creator badge. Preview looks institutional.
Paste any path into Facebook and the preview card looks real. The human who clicks gets a different path entirely.

Early Vercel-hosted variants did something clever with Facebook's own crawler. A normal browser hitting the deployment received a large Next.js decoy, often a furniture or generic business template with no obvious phishing content. Facebook's link preview bot (facebookexternalhit) received a 307 redirect to a route that returned almost nothing except Open Graph tags: official-looking Meta logo, title along the lines of "Official Notice from Facebook," description copy about a permanent creator badge. Paste any path on the deployment into Facebook and the preview card looked institutional. The human who clicked through got a different path entirely.

Fig F Capture stages
01
Identity
Name, page, role
02
Password
Primary credential
03
2FA code
SMS / app / email
04
Session
c_user + xs cookies
A stolen live session bypasses 2FA completely. Passwords and backup codes are fallback. Session material is the prize.

Capture flow was multi-stage. Identity and page details first. Password second. Two-factor codes third. The more dangerous variants preferred session material, Facebook c_user and xs cookie pairs, over passwords alone. A stolen live session bypasses 2FA completely because the session is already authenticated. Passwords and backup codes were collected as fallback.

Exfiltration clustered on two patterns:

  1. Telegram bots. Each victim step forwarded as a message into an operator chat. When the bot token was recoverable, the entire harvest pipeline became readable — and usable for authorized victim-rescue disruption.
  2. Serverless form backends. Endpoints on services like submit-form.com / Formspark and similar "paste a form, get a POST URL" products. Frontends rotate daily. Collection backends stick around longer, which matches the sticky collection backends Hunt.io told defenders to track.

Round 1: recover the bot, notify the victims

One Vercel-era kit shipped its Telegram bot token in client-side configuration. That is a sloppy mistake. It is also how victim rescue scales.

Fig G Round 1 outcome
3,400
FB credential/session records recovered
CAFC
Canadian victims routed
BURNED
Bot renamed, channel dead
Four months of intake on one bot. A clean takedown with zero outreach is a press release. A recovered exfil channel is how thousands of humans get a warning path.

With a live token you do not need to guess who got hit. You read the operator's own intake channel. Over roughly four months, one recovered bot in this cluster had accumulated about ~3,400 Facebook credential/session records captured in that intake. Canadian cases were routed through the Canadian Anti-Fraud Centre. The bot was renamed, the channel was burned from the operator's side, and where notification channels were available, affected users could be warned and advised to rotate credentials and sessions before the records aged into secondary fraud.

A clean takedown with zero outreach is a press release. A recovered exfil channel is how thousands of humans get a warning path. That is the point of the work.

Round 2: the operators read the post-mortem

They adapted quickly after the writeup landed.

Fig H They read the writeup. Then they shipped this.
Round 1
Client-side token
  • Bot token in browser bundle
  • Vercel static / Next decoy
  • cat the config, recover the chat
Round 2
Server-side only
  • Next.js Server Actions
  • Env vars on Render / peers
  • Laravel + ngrok / CF tunnels
Lure, anti-analysis, multi-stage UX still fingerprintable. Token no longer sits in the browser bundle. Assume your writeup is their sprint backlog.

Successor kits moved off plaintext client config onto Next.js Server Actions, with bot tokens held in server-side environment variables on Render and similar hosts. From the public internet you can still fingerprint the lure, the anti-analysis tooling, and the multi-stage UX. You cannot cat the token out of a browser bundle anymore. Parallel variants used Laravel backends fronted by ephemeral tunnels (ngrok, Cloudflare quick tunnels), which come up and down with the operator's laptop lid.

Git history still betrayed kit developers who committed fallback defaults and coursework credentials into public repositories. Language artifacts in helper files, Vietnamese comments and i18n bundles spanning a dozen-plus languages of Meta UI chrome, tied throwaway deploy accounts back into a common tooling culture even when the GitHub identities were week-old empties hosting dozens of deploy-* repos each.

Hosting rotated across Vercel, Render, Netlify, Wasmer, Surge, GitHub Pages, Cloudflare Pages, Neocities. The durable signals were page titles, template structure, collection backends, and exfil shape. The domain of the week was noise.

Case 3 - Shorteners, content farms, and burner rotation

By August 2026 a related Meta/Instagram credential network was running a cleaner separation of concerns.

Fig I Four layers. Kill the last hop and they respawn by afternoon.
L1
Lure content Sticky
WordPress SEO farms. Finance and marketing articles carrying the bait links.
L2
Shortener layer Sticky
Branded shortlink services. Campaign codes smuggled through UTM parameters.
L3
Dispatcher Sticky
Netlify page. JavaScript randomly selects among dozens of capture burners.
L4
Capture burners 48 blocked
Vercel deployments serving the actual credential UI. Disposable by design.
Vercel actioned the burner fleet hard. Shortener and dispatcher stayed up longer. Disruption has to climb the stack in parallel.

Vercel actioned the burner fleet hard once evidenced. Forty-eight hosts returned legal-block responses. The shortener layer and dispatcher stayed up longer. That is the architectural lesson. If you only kill the last hop, the operator respawns capture nodes behind the same rotation logic by afternoon. Disruption has to climb the stack: burners, dispatcher, shortener, content farm, registrar, CDN account, brand abuse desk, browser blocklists. In parallel. Not one ticket at a time.

Native-language comments in dispatcher code and corporate WHOIS on the shortener family pointed at a Vietnamese-speaking operation running behind a US-registered LLC shell. Same region as a lot of the Bluetick tooling. Read that as density of talent and infrastructure. It is not a courtroom-ready claim of one single gang.

One doctrine across three channels

SMS tax scare. Facebook blue-tick flattery. Instagram password-reset shortlink. Different inboxes. Same underlying machine.

Map One machine, six layers
Layer What to take
Delivery SMS, social graph, SEO+shortlink. Costume layer.
Lure Anxiety (tax, suspension) or aspiration (badge, unlock)
Kit Multi-stage capture, anti-bot gates, often live relay or session theft
Host Bulletproof colo or disposable PaaS burners behind rotation
Exfil Telegram bots or serverless form backends. This is where the real mass sits.
Cash-out Account takeover, resale, ads fraud, secondary phishing as the victim

The working playbook that came out of these engagements:

Fig J Working playbook
1

Enumerate the kit, ahead of the domain

Domains die in days. Bundle strings, page titles, dispatcher JavaScript, and exfil shapes survive rotation.

2

Hunt the exfil channel first

A recovered Telegram bot token or a sticky form-backend URL is worth more than twenty burner takedowns. That is how you see victims.

3

Victims first, infrastructure second

Notify people. Route Canadians through CAFC. Then burn the hosts. That order matters.

4

Where authorized, poison when you cannot seize

Where authorized, poisoning can degrade an intake pipeline when seizure is not available. If the intake is open and the token is locked down, realistic fakes can make the operator's database a liability. Mark canaries privately.

5

Abuse in parallel

Host platform, CDN, registrar, impersonated brand, Google Safe Browsing, APWG, national CERT. Serial reporting is how campaigns outlive your attention span.

6

Attribute when OPSEC fails, then hand it off

Student emails in git history, payment rails, corporate shells. Publish techniques. Pass identities to people with warrants.

7

Assume your writeup is their sprint backlog

Round 1 plaintext tokens became Round 2 server-side env vars. Public research gets mocked in operator bot bios. The correct response is still to move anyway.

What defenders and platforms should change

Individuals

CRA, banks, and major platforms do not cold-text you magic links to "review" or "verify" under threat of loss. Open the app or type the official domain yourself. Forward suspected spam texts to 7726 where your carrier supports it, and report fraud or cybercrime to the Canadian Anti-Fraud Centre. If you typed a password into a fake page, rotate it from a clean device and kill active sessions. If it was Facebook, revoke sessions and review connected apps immediately.

Enterprises

AiTM kits with valid brand certificates on bulletproof IP space mean MFA alone is incomplete. Prefer phishing-resistant authenticators (passkeys, hardware-bound keys) over SMS or approve/deny prompts that a live relay can simply forward. Monitor for reverse-proxy infrastructure patterns in your threat intel feeds. Lookalike domains are only one slice of the problem.

Burner hosts (Vercel, Render, Netlify)

Faster 451s when evidence is tight. The gap is correlation: forty-eight burners behind one dispatcher should land as one case instead of forty-eight tickets. Share dispatcher and shortener fingerprints across trust-and-safety teams the way browser vendors share Safe Browsing signals.

Meta and peer platforms

Crawler-specific cloaking that serves institutional OG cards to facebookexternalhit while serving decoys to users is a solved detection class if you compare the two responses on every reported URL. Session-cookie theft should trigger the same severity path as password breaches. Blue-tick and page-appeal lure language is stable enough to be a proactive classifier. Waiting on a reactive abuse queue is too slow.

Carriers and SMS aggregators

The CRA campaign's expensive hop was the text itself. A2P and traffic-pumping controls catch some of this. They miss targeted, low-volume, high-believability sends. Cross-carrier threat exchange on message body templates and landing domains still lags email by a decade.

Why this work

I build security and intelligence systems for a living, including SCAFU. These engagements were concrete operations against live theft pipelines aimed at real people: Canadian taxpayers staring at a fake CRA spinner while someone tested their password, and Facebook page owners who thought Meta had finally given them a badge.

The through-line to everything else I ship is evidence-grade truth. Kits leave artifacts. Operators reuse strings. Exfil channels concentrate risk. Document those things carefully enough to survive adversarial scrutiny and you can move platforms, warn victims, and occasionally put a name and a payment rail in front of someone who can do more than write a blog post.

Smishing is the SMS door into the same credential economy that runs on blue-tick lures and shortlink laundering. Treat the channel as a detail. Hunt the kit. Recover the exfil when authorized. Tell the victims. Burn what is left. Then assume they are already building the next version.

Portions of the CRA case were first published as a technical thread in March 2026. Public campaign context on related ClickFix tradecraft and Meta-focused session theft draws on reporting by Hunt.io and Unit 42 alongside direct kit analysis. CRA scam-recognition guidance: canada.ca. Operational details that would help copycats or expose uninvolved third parties are withheld. Counsel-grade briefing: SCAFU Investigations.

← Back to Blog