IronToll: Global Government-Impersonation Phishing-as-a-Service Campaign
Score: 9/10

IronToll: Global Government-Impersonation Phishing-as-a-Service Campaign

The IronToll campaign utilizes the 'Iron Man System' PhaaS kit to conduct global government and brand impersonation for real-time credential and OTP theft.

Executive Summary

PhishEye Research has documented IronToll, a large-scale phishing-as-a-service (PhaaS) campaign leveraging the Chinese-language 'Iron Man System' (钢铁侠) kit. The operation targets over 10 countries by impersonating national e-government portals, tax authorities, and logistics brands. It is part of the broader Smishing Triad ecosystem, sharing tactical overlaps with actors like Darcula and the Mouse System.

The technical core of IronToll is its live-interception capability, using real-time operators to relay stolen credentials and SMS one-time passwords (OTPs) to legitimate services via encrypted WebSockets. The infrastructure is hosted directly on Tencent and Alibaba Cloud, deliberately bypassing common CDN proxies like Cloudflare. The kit employs sophisticated cloaking techniques, including mobile-only rendering and IP-intelligence filtering, to evade automated sandboxes and desktop-based security scanners.

This threat poses a high risk to sectors relying on SMS-based multi-factor authentication. The campaign's industrial scale and rapid domain rotation (every 1-2 days) necessitate monitoring of durable indicators such as command-and-control (C2) IPs and kit-specific fingerprints rather than individual URLs.

Key Details

Threat Name

IronToll Phishing Campaign

Affects

—

Adversary

Smishing Triad Other Adversaries and Aliases: Darcula; Phoenix; Xiū gǒu; YYlaiyu; Panda Shop; Lighthouse

Malware/Tools

Iron Man System, Mouse System, Darcula, Phoenix, Lighthouse, Panda Shop, YYlaiyu, Xiū gǒu

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance7
Enterprise Relevance8
Clarity & Structure10
Technical Depth8

Sources