Group-IB Unmasks Smishing Error524 Phishing Operation Hiding Behind Fake Cloudflare Error Pages

Group-IB Unmasks "Smishing Error524" — a 4,389-Domain Phishing Operation Hiding Behind Fake Cloudflare Error Pages

Group-IB has exposed a long-running smishing operation that weaponizes a deceptively simple trick: when a security researcher or automated scanner visits one of its phishing pages, the site serves a fake Cloudflare error screen — most often the 524 timeout — making the malicious infrastructure look like a broken website. Real victims, filtered by geolocation and device type, see a pixel-perfect credential harvester instead.

Tracked internally as Smishing Error524 and active since the second half of 2025, the campaign spans 4,389 phishing domains impersonating more than 267 brands across 72 countries, with Latin America as its primary theatre. Group-IB's Digital Risk Protection team assesses it as one of the more disciplined phishing-as-a-service operations it has analyzed.

The Error 524 deception layer

The operationally distinctive feature is a dual-layer anti-analysis architecture. Requests that fail the kit's checks — non-targeted geolocation, a desktop user-agent, or missing session parameters — receive a page visually identical to a Cloudflare gateway error. The 524 timeout screen is the default, with 300 and 313 variants also observed.

This decoy serves two purposes at once. It denies researchers and automated crawlers any indicators of malicious content, and it gives hosting providers reviewing abuse reports a plausible "the site is just broken" explanation — slowing takedowns. Filtering is enforced entirely client-side: the page calls external IP geolocation APIs to confirm a victim's country, currency, and language, then validates a mobile user-agent before rendering anything malicious. Group-IB rates this conditional-rendering discipline as well above the norm for phishing-as-a-service.

Scope and targeting

Per Group-IB, Mexico is the hardest-hit market with 1,851 domains, followed by Chile (529) and Colombia (258). The Netherlands and Germany lead European exposure, Australia leads APAC, and North American activity concentrates on financial services and consumer rewards programs.

By sector, telecommunications dominates with 1,754 domains, followed by financial services (696) and loyalty or rewards programs (488). Operators lean on three urgency pretexts: expiring loyalty points, unclaimed rewards, and pending package deliveries — all designed to trigger a fast, low-scrutiny tap on a mobile device.

Roughly 30 percent of the infrastructure sits on Tencent Cloud and Alibaba (US) origin servers, fronted by Cloudflare (AS13335) to mask the true hosting IPs.

Attack chain

Victims who clear the geofencing checks receive an SMS spoofed to a local number containing a shortened URL. The landing page loads a minimal Single Page Application skeleton — a single <div id="app"> mount point — whose actual content is Base64-encoded inside custom HTML elements and decoded at runtime, defeating static analysis entirely.

From there, the kit progressively harvests personal identifiers before soliciting full credit card credentials. The most notable technical detail: stolen card data is exfiltrated in real time over an encrypted WebSocket channel, using binary-encoded payloads and heartbeat pings to keep the connection alive. This gives operators live access to credentials as victims type them, rather than waiting for a form submission — enabling immediate fraud or real-time relay through anti-fraud checks.

Indicators of Compromise

Group-IB names the following operator infrastructure (defanged — re-arm only in controlled environments):

Assessment

We assess with high confidence that Smishing Error524 is a financially motivated phishing-as-a-service cluster rather than a state-aligned program — based on the breadth of impersonated retail and telecom brands, the use of commodity cloud hosting under Cloudflare cover, and the singular focus on credit card monetization.

We further assess with moderate confidence that the Latin American concentration reflects weak SMS anti-spoofing enforcement by regional carriers and the cultural prevalence of telecom and retail loyalty programs as social-engineering pretexts, rather than any geographic tie to the operators themselves.

Defenders should treat the listed IPs and the Cloudflare-fronted SPA pattern as hunting leads. The highest-value detection opportunity is behavioral: alert on browser sessions that fetch external IP geolocation data immediately before rendering a credential form — a sequence that is rare in legitimate traffic but core to this kit's logic. Group-IB tracks the cluster as Smishing Error524; the operator is not currently mapped to a named actor in IntelFusions' Atomic Fusion taxonomy.

Source: Group-IB — Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages. This briefing is provided by IntelFusions for informational and defensive purposes only. Analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named.

Read the full analysis on IntelFusions