Threat reportPhishingTL-2026-1032
Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using Darcula and Phoenix PhaaS Platforms
Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using (TL-2026-1032), also tracked as Putevi Srbije Smishing Campaign, is a medium-severity phishing campaign, first published 2026-07-01. It is attributed to Phoenix PhaaS customers with low confidence, affects Putevi Srbije Public brand / road-fine payment portal (impersonated), maps to 20 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 1Phoenix PhaaS customers
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-1032
- Threat ID
- TL-2026-1032
- Also known as
- Putevi Srbije Smishing Campaign, Serbian Traffic Fine Smishing
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution
- Phoenix PhaaS customers
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, transport, finance, consumer citizens
- Target regions
- serbia, Balkans, Europe, APAC, LATAM, MEA
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using
Malware and tooling: Darcula PhaaS platform, Phoenix PhaaS platform, Puppeteer
How Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using works
A smishing campaign impersonates Putevi Srbije, Serbia's state road authority, sending fake traffic-fine notices with urgency and penalty-increase threats that lead to counterfeit government payment portals harvesting payment card data. Group-IB identified typosquatted domains and infrastructure spanning two distinct Phishing-as-a-Service (PhaaS) platforms, Darcula and Phoenix, indicating fraudsters are mixing multi-vendor phishing tooling within a single operation.
In a campaign discovered by Group-IB on July 1, 2026, cybercriminals impersonated Putevi Srbije, the Serbian public enterprise responsible for national road infrastructure, to defraud victims via SMS phishing (smishing). Victims receive text messages claiming an outstanding traffic fine, using urgency language warning that the penalty amount will increase if not paid immediately. The message contains a link to a cloned government payment portal built to closely mimic the real Putevi Srbije domain and branding.
The operation is notable for blending infrastructure and toolkits from two separate Phishing-as-a-Service (PhaaS) ecosystems: Darcula, a Chinese-language platform that emerged in 2023 offering 200+ ready-made phishing templates and, in its newer iterations, AI-generated pages, Puppeteer-based browser automation, and iMessage/RCS delivery to bypass SMS firewalls; and Phoenix, a centralized administrative-panel PhaaS platform (linked to Reward Points and Failed Parcel Delivery phishing campaigns since January 2024) that gives operators real-time victim telemetry, geofencing, IP filtering, and live-phishing intervention across localized templates for APAC, LATAM, Europe, and MEA regions.
The phishing pages hosted on both platform's infrastructure use significant client-side evasion engineering: content is Base64-encoded and embedded inside custom, non-standard HTML tags (e.g. z-span, z-strong) rather than plain text, defeating static keyword/signature scanners. The obfuscated content is only decoded and rendered client-side via decodeURIComponent(atob(...)) calls, deferred using requestIdleCallback so decoding happens during browser idle cycles, and gated behind the IntersectionObserver API so text is only decoded once it scrolls into the visible viewport. A recurring 2-second polling loop continuously rescans the DOM for newly injected obfuscated nodes, ensuring dynamically added content is also decoded. The phishing infrastructure additionally sits behind Cloudflare/CDN proxy fronting to obscure the true hosting origin and frustrate takedown attempts.
Once a victim submits payment card data (card number, expiry date, CVV) on the fraudulent portal, the data is harvested directly by the operators for immediate fraudulent purchases, resale on dark web card shops, or follow-up social-engineering scams. Victims typically first learn of the compromise via unexpected bank account charges.
The campaign demonstrates a broader financial-fraud trend of PhaaS interoperability: rather than committing to a single phishing-kit vendor, criminal operators appear to be mixing and matching templates, hosting, and back-end panels from multiple competing PhaaS providers within one operation, complicating attribution and blocklist-based defenses that assume a single infrastructure fingerprint per campaign.
MITRE ATT&CK techniques used in TL-2026-1032
Collection
T1005 Data from Local System; T1119 Automated Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Command and Control
T1071 Application Layer Protocol; T1090 Proxy
command-and-control
Execution
Credential Access
T1528 Steal Application Access Token
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
Reconnaissance
T1591 Gather Victim Org Information
Impact
stealth
Affected products and versions in Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using
- Putevi Srbije — Public brand / road-fine payment portal (impersonated)
Vulnerable versions: N/A - brand impersonation, not a software vulnerability
Remediation for Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using
Immediate actions
- Block/monitor the identified typosquatted Putevi Srbije domains at DNS/perimeter and mobile carrier SMS filters
- Alert Serbian banks and card issuers to monitor for fraudulent transactions tied to the campaign timeframe
- Report and request takedown of Cloudflare/CDN-fronted phishing domains via abuse channels
- Publish a public advisory from Putevi Srbije / Serbian CERT clarifying the agency never requests card payment via SMS links
Workarounds
- Do not click payment links received via unsolicited SMS claiming to be traffic fines; navigate to putevisrbije.rs directly instead
- Card issuers can apply velocity/geo anomaly rules to catch first-use fraudulent transactions from harvested cards
Longer-term hardening
- Deploy carrier-level RCS/SMS content filtering that inspects rendered (post-JS-decode) page content, not just raw markup
- Adopt brand-protection / typosquat-monitoring services to catch new lookalike domain registrations early
- Share IOCs (domains, obfuscation patterns) with regional CERTs and PhaaS-tracking threat-intel communities
- Educate citizens on verifying government payment notices only via official .gov/.rs channels, never SMS links
Weaknesses (CWE) in Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using
Timeline of Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using
- Darcula Chinese-language PhaaS platform emerges, offering 200+ phishing templates targeting government, financial, and logistics brands
- Phoenix PhaaS platform activity begins, driving Reward Points and Failed Parcel Delivery smishing campaigns globally
- Netcraft and other researchers report Darcula's shift to iMessage/RCS delivery to bypass SMS firewalls, targeting postal services worldwide
- Group-IB publishes 'Phoenix Rising' research exposing the Phoenix PhaaS kit's admin panel, geofencing, and real-time victim monitoring capabilities
- Help Net Security reports on the broader growth and maturation of Chinese-language phishing-as-a-service ecosystems including Darcula
- Typosquatted Putevi Srbije lookalike domains observed registered across .cc, .help, .homes, .top, and .icu TLDs ahead of active campaign
- Serbian road users report receiving urgent SMS traffic-fine notices directing them to fraudulent payment portals
- Group-IB publishes research disclosing the active Putevi Srbije traffic-fine smishing campaign, identifying dual Darcula/Phoenix infrastructure
Sources cited for Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using
- Group-IB: Balkans fake traffic fines phishing campaign
- Group-IB: Phoenix Rising - Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns
- BleepingComputer: New Darcula phishing service targets iPhone users via iMessage
- Infosecurity Magazine: Darcula Phishing as a Service Operation Snares 800,000+ Victims
- Netcraft: 'darcula' iMessage and RCS smishing attacks target USPS and global postal services
- The Hacker News: Darcula Phishing Network Leveraging RCS and iMessage to Evade Detection
- Help Net Security: Chinese phishing gangs grow into a force to be reckoned with
- SC Media: 'darcula' phishing platform targets postal organizations worldwide
- Dark Reading: Phishing Kit Darcula Gets Lethal AI Upgrade
- Field Effect: 'Darcula' phishing service targeting Android and iPhone users
- PhishFirewall: Understanding Darcula - The New Phishing-as-a-Service Threat
- Wikipedia: Darcula (phishing platform)
- Cyber Security News: New PhaaS Platform Phoenix Drives Brand-Impersonation Smishing Across Finance, Telecom, and Logistics
- CyberPress: New Phoenix Platform Drives Brand-Impersonation Smishing
Detection coverage for TL-2026-1032
As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1032 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.