Executive Summary
PhishEye Research has documented IronToll, a large-scale phishing-as-a-service (PhaaS) campaign leveraging the Chinese-language 'Iron Man System' (钢铁侠) kit. The operation targets over 10 countries by impersonating national e-government portals, tax authorities, and logistics brands. It is part of the broader Smishing Triad ecosystem, sharing tactical overlaps with actors like Darcula and the Mouse System.
The technical core of IronToll is its live-interception capability, using real-time operators to relay stolen credentials and SMS one-time passwords (OTPs) to legitimate services via encrypted WebSockets. The infrastructure is hosted directly on Tencent and Alibaba Cloud, deliberately bypassing common CDN proxies like Cloudflare. The kit employs sophisticated cloaking techniques, including mobile-only rendering and IP-intelligence filtering, to evade automated sandboxes and desktop-based security scanners.
This threat poses a high risk to sectors relying on SMS-based multi-factor authentication. The campaign's industrial scale and rapid domain rotation (every 1-2 days) necessitate monitoring of durable indicators such as command-and-control (C2) IPs and kit-specific fingerprints rather than individual URLs.
Key Details
Threat Name
IronToll Phishing Campaign
Affects
—
Adversary
Smishing Triad Other Adversaries and Aliases: Darcula; Phoenix; Xiū gǒu; YYlaiyu; Panda Shop; Lighthouse
Malware/Tools
Iron Man System, Mouse System, Darcula, Phoenix, Lighthouse, Panda Shop, YYlaiyu, Xiū gǒu
