{"id":37,"date":"2026-02-06T20:18:51","date_gmt":"2026-02-06T20:18:51","guid":{"rendered":"http:\/\/localhost\/?p=37"},"modified":"2026-02-06T20:18:51","modified_gmt":"2026-02-06T20:18:51","slug":"ongoing-phishing-smishing-campaign","status":"publish","type":"post","link":"https:\/\/securityblog.denison.edu\/index.php\/2026\/02\/06\/ongoing-phishing-smishing-campaign\/","title":{"rendered":"Ongoing phishing\/smishing campaign"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Denison&#8217;s cybersecurity intelligence has observed a persistent, multi-stage phishing and smishing campaign. We track this threat actor as <em>BLUECRAB<\/em>, and we have observed them before.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The threat actors use a similar pattern of behavior:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Using a maliciously crafted email, phish a victim and steal both the victim&#8217;s password and the victim&#8217;s personal cell phone number.<\/li>\n\n\n\n<li>Send a second &#8220;smish&#8221; (phish via SMS) to the victim, claiming that the victim&#8217;s account is pending deactivation, and engage them in a conversation.<\/li>\n\n\n\n<li>When the victim replies, attempt to log in as the victim, using the phished password.<\/li>\n\n\n\n<li>On the multi-factor authentication (Duo) step, choose SMS. Simultaneously tell the victim that they need to verify their cell phone number by sending a SMS code, and to send that code in the same text message thread.<\/li>\n\n\n\n<li>Use the smished multi-factor authentication code to log in as the user, then change the password.<\/li>\n\n\n\n<li>Send other users more phishing messages, either to steal credentials or money.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The &#8220;smish&#8221; message might look something like:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attacker:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Hello is this [victim name]?<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Attacker:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Confirm if you applied to terminate your current school email (&lt;username&gt;[@]denison[.]edu)Confirm YES or NO (So NO means that I don&#8217;t want to terminate my email) to avoid complete shutdown of your email and loss of all your files.<br>Helpdesk[@]denison[.]edu<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Victim:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">NO<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Attacker:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Alright! If [XXXX] matches the last 4 digits of the phone number on your profile account. You will a text from the system now with a code. Which is what you will text back to avoid account shutdown. Okay?<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Victim:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">okay<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Attacker:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">A verification code sent to your phone, what is the code?<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Victim:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">[XXXXXXX]<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Attacker:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Okay<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">At this point, the attacker has successfully gained access to the victim&#8217;s account. From here, we have observed them doing several things:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Directly phishing other users within the denison[.]edu domain<\/li>\n\n\n\n<li>Directly attempting to scam for money<\/li>\n\n\n\n<li>Schedule or delay sending messages, to be sent (even after the account is remediated)<\/li>\n\n\n\n<li>Changing email settings to obfuscate their tracks<\/li>\n\n\n\n<li>Deleting email messages that indicate malicious intent<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Never give out a multi-factor authentication code that you did not request yourself! Never provide your password anywhere EXCEPT for Denison&#8217;s single sign-on page. You can verify the login page by checking the address bar: the domain should be <em>identity.denison.edu<\/em>. And, if you receive a suspicious email message, forward it to <a href=\"mailto:isitsafe@denison.edu\">isitsafe@denison.edu<\/a> to report it as phishing.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Denison&#8217;s cybersecurity intelligence has observed a persistent, multi-stage phishing and smishing campaign. The threat actors use a similar pattern of behavior, using a maliciously crafted email to phish a victim and steal both the victim&#8217;s password and the victim&#8217;s personal cell phone number. The attacker then smishes the user and steals a multi-factor authentication code to access the victim&#8217;s account. With the account, they send other users more phishing messages, either to steal credentials or money.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-37","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts\/37","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/comments?post=37"}],"version-history":[{"count":0,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/posts\/37\/revisions"}],"wp:attachment":[{"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/media?parent=37"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/categories?post=37"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securityblog.denison.edu\/index.php\/wp-json\/wp\/v2\/tags?post=37"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}