A criminal service sold over Telegram is letting anyone with a little money send mass text messages under a bank's name, and have them appear inside the same conversation thread as that bank's real alerts. Colombia's national cyber emergency response team, colCERT, described the service in a TLP:CLEAR alert on 3 August and rated the risk high.
It is marketed as Andy bulk SMS through the Telegram channel @AndyWu_SMS291, on a Crime-as-a-Service model: the operator runs the sending infrastructure, the buyer supplies the target list and the message. Its selling point is a custom alphanumeric Sender ID, the short name that appears as the sender in place of a phone number. Because phones group messages by that sender name, a fraudulent text sent under a bank's alpha sender drops into the victim's existing thread of genuine banking messages, under the same heading, right below texts they know are real. colCERT notes in its alert that this also blunts the conventional detection mechanisms mobile operators rely on.
What the seller's own ads show
The strongest evidence in the alert comes from the operator's own marketing. colCERT says the actor published promotional material documenting campaigns already run against customers of European financial institutions, including CaixaBank in Spain and Santander in Portugal.
- Santander (Portugal): messages in Portuguese imitating "Transferencia Nacional" notifications for amounts such as 1.435 EUR.
- CaixaBank (Spain): messages in Spanish asking the recipient to confirm a transfer of 17.092,83 euros with a code, or to call a number on an international prefix beginning +3493.
The pattern is smishing followed by vishing. The text manufactures the panic of a large transfer the victim did not make, and the victim either taps a fake verification link or calls a fake support line, where a human operator talks them through handing over credentials or one-time codes. Neither bank was breached. Their customers are the targets and their brand is the disguise.
Why Colombia is in scope
colCERT flagged the service because the seller explicitly lists Colombia within its market coverage, alongside more than 200 countries. That is the operative detail. No local capability has to be built and no vulnerability has to be found: the infrastructure to impersonate Colombian banks and government bodies by SMS is already on sale, cheaply and anonymously, to buyers at home or abroad. colCERT has issued a run of alerts in the past week, and our Colombia profile tracks the wider picture.
What you should do
For consumers, one rule now carries the weight: the thread a message arrives in proves nothing. Sender ID is a display label, not an authentication mechanism, and spoofing it here is a purchase rather than an attack. Never call a number or open a link supplied by a text about your money. Leave the message, open the bank's own app, or dial the number printed on the back of your card.
For banks and mobile operators, the lever that works is Sender ID registration. In markets where alphanumeric senders must be registered and unregistered ones are dropped rather than delivered, a service like this loses most of its value. Where registration is voluntary or unenforced, filtering on message content will keep losing, because the content of these messages is a near-perfect copy of the real thing. Our earlier reporting on a smishing operation that hid behind fake Cloudflare error pages showed the same asymmetry on the infrastructure side.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.