# Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using Darcula and Phoenix PhaaS Platforms

> A smishing campaign impersonates Putevi Srbije, Serbia's state road authority, sending fake traffic-fine notices with urgency and penalty-increase threats that lead to counterfeit government payment portals harvesting payment card data. Group-IB identified typosquatted domains and infrastructure spanning two distinct Phishing-as-a-Service (PhaaS) platforms, Darcula and Phoenix, indicating fraudsters are mixing multi-vendor phishing tooling within a single operation.

- **Published:** 2026-07-01T00:00:00Z
- **Last reviewed:** 2026-07-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1032
- **ID:** TL-2026-1032
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** Phoenix PhaaS customers
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In a campaign discovered by Group-IB on July 1, 2026, cybercriminals impersonated Putevi Srbije, the Serbian public enterprise responsible for national road infrastructure, to defraud victims via SMS phishing (smishing). Victims receive text messages claiming an outstanding traffic fine, using urgency language warning that the penalty amount will increase if not paid immediately. The message contains a link to a cloned government payment portal built to closely mimic the real Putevi Srbije domain and branding.

The operation is notable for blending infrastructure and toolkits from two separate Phishing-as-a-Service (PhaaS) ecosystems: Darcula, a Chinese-language platform that emerged in 2023 offering 200+ ready-made phishing templates and, in its newer iterations, AI-generated pages, Puppeteer-based browser automation, and iMessage/RCS delivery to bypass SMS firewalls; and Phoenix, a centralized administrative-panel PhaaS platform (linked to Reward Points and Failed Parcel Delivery phishing campaigns since January 2024) that gives operators real-time victim telemetry, geofencing, IP filtering, and live-phishing intervention across localized templates for APAC, LATAM, Europe, and MEA regions.

The phishing pages hosted on both platform's infrastructure use significant client-side evasion engineering: content is Base64-encoded and embedded inside custom, non-standard HTML tags (e.g. z-span, z-strong) rather than plain text, defeating static keyword/signature scanners. The obfuscated content is only decoded and rendered client-side via decodeURIComponent(atob(...)) calls, deferred using requestIdleCallback so decoding happens during browser idle cycles, and gated behind the IntersectionObserver API so text is only decoded once it scrolls into the visible viewport. A recurring 2-second polling loop continuously rescans the DOM for newly injected obfuscated nodes, ensuring dynamically added content is also decoded. The phishing infrastructure additionally sits behind Cloudflare/CDN proxy fronting to obscure the true hosting origin and frustrate takedown attempts.

Once a victim submits payment card data (card number, expiry date, CVV) on the fraudulent portal, the data is harvested directly by the operators for immediate fraudulent purchases, resale on dark web card shops, or follow-up social-engineering scams. Victims typically first learn of the compromise via unexpected bank account charges.

The campaign demonstrates a broader financial-fraud trend of PhaaS interoperability: rather than committing to a single phishing-kit vendor, criminal operators appear to be mixing and matching templates, hosting, and back-end panels from multiple competing PhaaS providers within one operation, complicating attribution and blocklist-based defenses that assume a single infrastructure fingerprint per campaign.

## MITRE ATT&CK

- T1591 Gather Victim Org Information
- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1588 Obtain Capabilities
- T1585 Establish Accounts
- T1608 Stage Capabilities
- T1566 Phishing
- T1204 User Execution
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1102 Web Service
- T1684.001 Impersonation
- T1036 Masquerading
- T1528 Steal Application Access Token
- T1005 Data from Local System
- T1119 Automated Collection
- T1071 Application Layer Protocol
- T1090 Proxy
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft

## Sources

- [Group-IB: Balkans fake traffic fines phishing campaign](https://www.group-ib.com/blog/balkans-fake-traffic-fines-phishing/)
- [Group-IB: Phoenix Rising - Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns](https://www.group-ib.com/blog/phoenix-phaas-kit-smishing/)
- [BleepingComputer: New Darcula phishing service targets iPhone users via iMessage](https://www.bleepingcomputer.com/news/security/new-darcula-phishing-service-targets-iphone-users-via-imessage/)
- [Infosecurity Magazine: Darcula Phishing as a Service Operation Snares 800,000+ Victims](https://www.infosecurity-magazine.com/news/darcula-phishing-as-a-service/)
- [Netcraft: 'darcula' iMessage and RCS smishing attacks target USPS and global postal services](https://www.netcraft.com/blog/darcula-smishing-attacks-target-usps-and-global-postal-services)
- [The Hacker News: Darcula Phishing Network Leveraging RCS and iMessage to Evade Detection](https://thehackernews.com/2024/03/darcula-phishing-network-leveraging-rcs.html)
- [Help Net Security: Chinese phishing gangs grow into a force to be reckoned with](https://www.helpnetsecurity.com/2026/05/26/chinese-language-phishing-services/)
- [SC Media: 'darcula' phishing platform targets postal organizations worldwide](https://www.scworld.com/news/darcula-phishing-platform-targets-postal-organizations-worldwide)
- [Dark Reading: Phishing Kit Darcula Gets Lethal AI Upgrade](https://www.darkreading.com/remote-workforce/phishing-kit-darcula-gets-major-ai-upgrade)
- [Field Effect: 'Darcula' phishing service targeting Android and iPhone users](https://fieldeffect.com/blog/darcula-phishing-service-targeting-android-and-iphone-users)
- [PhishFirewall: Understanding Darcula - The New Phishing-as-a-Service Threat](https://www.phishfirewall.com/post/understanding-darcula-the-new-phishing-as-a-service-threat)
- [Wikipedia: Darcula (phishing platform)](https://en.wikipedia.org/wiki/Darcula)
- [Cyber Security News: New PhaaS Platform Phoenix Drives Brand-Impersonation Smishing Across Finance, Telecom, and Logistics](https://cybersecuritynews.com/new-phaas-platform-phoenix/)
- [CyberPress: New Phoenix Platform Drives Brand-Impersonation Smishing](https://cyberpress.org/phoenix-drives-brand-smishing/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1032
