Thursday, May 15, 2025
HomeAndroidHackers Exploit the SMS Gateway to Sent Text Millions of U.S Phone...

Hackers Exploit the SMS Gateway to Sent Text Millions of U.S Phone Numbers

Published on

SIEM as a Service

Follow Us on Google News

Hackers who have compromised SmartTVs, Chromecast devices and thousands of vulnerable printers to promote PewDewPie Youtube channel, now back to form and exploits the SMS gateways to send a text to millions of Peoples in the U.S.

Hackers with the name of @j3ws3r, @0xGiraffe in Twitter, taking advantage of the vulnerability that resides in the SMS gateways that are used by businesses to send mass text messages to users.

Hackers said that paid SMS services provide email gateways are extremely vulnerable, and a simple PHP command can send an SMS message to any number used by major mobile phone networks.

- Advertisement - Google News

How did they Exploit SMS gateways

Initially, Hacktivist @j3ws3r separates a U.S phone number from 32GB list of 7.2 billion potential phone numbers by writing a script that would help to isolate the U.S phone numbers by applying pre-existing US area codes.

Later they were used the filtered list to send an email to every U.S number that they have generated via mailx, a Unix command, through SMS gateways.

Hackers specifically target the 26 different email addresses, which are act as a gateway for major U.S ISP networks.

https://twitter.com/JoshPescatore/status/1156755662027788288

According to Hacktivist @j3ws3r who have shared details in private conversation to Wired, “From my private research a malicious person could easily screw up lots of phones, Malicious actors could use this to phish or get people to click on links they shouldn’t,” 

He also shared the Screenshot of the text message that posed as it comes from nsa.gov domain email address that is completely spoofed addresses to trick users to click on a link associated with it.

This kind of vulnerabilities in SMS gateways let attackers perform phishing on the victims that tricks to steal the personal data and the attacker also can infect the device with malware and spy on the user’s device activities.

“@j3ws3r says phones on AT&T, the United States’ largest mobile phone network, wouldn’t be able to block mass spoofed messages. “Instead of receiving one text from the spoofed email, for some reason AT&T randomises it,” he says. “If I sent 1,000 messages to an AT&T phone using their gateway you’ll get 1,000 separate messages that you can’t block since they aren’t from one sender.”

Hacktivist sent the messages to only very few to the targeted numbers  Because of the large scale of the phone numbers they’re trying to target, their script is likely to take some time to run and it is clearly showing the failing blocked by network operators.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Leverage Weaponized HTML Files to Deliver Horabot Malware

A recent discovery by FortiGuard Labs has unveiled a cunning phishing campaign orchestrated by...

TA406 Hackers Target Government Entities to Steal Login Credentials

The North Korean state-sponsored threat actor TA406, also tracked as Opal Sleet and Konni,...

Google Threat Intelligence Releases Actionable Threat Hunting Technique for Malicious .desktop Files

Google Threat Intelligence has unveiled a series of sophisticated threat hunting techniques to detect...

New Adobe Photoshop Vulnerability Enables Arbitrary Code Execution

Adobe has released critical security updates addressing three high-severity vulnerabilities (CVE-2025-30324, CVE-2025-30325, CVE-2025-30326) in...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

PoC Exploit Published for macOS Sandbox Escape Vulnerability (CVE-2025-31258)

Security researchers have disclosed a new macOS sandbox escape vulnerability tracked as CVE-2025-31258, accompanied...

New Advanced Phishing Attack Exploits Discord to Target Crypto Users

Check Point Research has uncovered a sophisticated phishing campaign that leverages Discord to target...

Android Security Update -A Critical RCE Vulnerability Actively Exploited in the Wild 

Google has released critical security patches for Android devices to address 57 vulnerabilities across...