Wednesday, May 7, 2025
HomeCyber Security NewsNew SMS-Based Phishing Tool 'DevilTraff' Enables Mass Cyber Attacks

New SMS-Based Phishing Tool ‘DevilTraff’ Enables Mass Cyber Attacks

Published on

SIEM as a Service

Follow Us on Google News

Cybersecurity experts are sounding the alarm about a new SMS-based phishing tool, Devil-Traff, that is enabling large-scale cyberattacks worldwide.

By exploiting trust and leveraging advanced automation, this malicious platform empowers attackers to conduct high-volume phishing campaigns with devastating results.

How Phishing Works Through SMS

Imagine an employee receives a seemingly legitimate text message from their bank: “Suspicious activity detected on your account.

- Advertisement - Google News

Click here to secure your account.” Or perhaps a message mimicking IT support: “Your password will expire soon. Click here to reset it.” 

At first glance, these messages appear credible, often tricking recipients into clicking malicious links or sharing sensitive information.

Using tools like Devil-Traff, cybercriminals can send thousands of such fraudulent messages within minutes.

A single misstep—such as entering credentials into a phishing site—can lead to compromised accounts, unauthorized access to sensitive systems, or even large-scale data breaches.

What Is Devil-Traff?

As per a report by Slash Next, Devil-Traff is a bulk SMS service that has become a favorite amongst cybercriminals.

Its features include customizable sender IDs, API integration for automated campaigns, and support for “black content,” which refers to malicious or illegal messaging.

The official sales thread for Devil-Traff SMS platform
The official sales thread for Devil-Traff SMS platform

These capabilities allow attackers to impersonate trusted organizations such as banks, government offices, or tech companies.

For example, cybercriminals might send messages appearing to be from “PayPal Support,” alerting users to suspicious activity and urging them to click a fraudulent link.

Another common attack involves intercepting one-time passwords (OTPs). By posing as service providers, attackers can trick victims into revealing OTPs, bypassing two-factor authentication (2FA), and gaining access to sensitive accounts.

Part of the user dashboard for Devil-Traff SMS platform
Part of the user dashboard for Devil-Traff SMS platform

Devil-Traff’s primary strength lies in its advanced automation and scalability. Through API integration, attackers can automate entire phishing campaigns with minimal manual effort, sending thousands of SMS messages across multiple countries in minutes.

The platform also uses macros to optimize delivery rates and bypass spam filters, ensuring a higher success rate for phishing attempts.

At a cost as low as $0.02 per message, Devil-Traff is an affordable and highly efficient tool for cybercriminals.

The popularity of bulk SMS platforms like Devil-Traff is rising within cybercrime forums, where users exchange tips, phone number databases, and strategies for optimizing campaigns.

These marketplaces even offer private routes—for example, using specific sender IDs such as “Binance Support”—to maximize the effectiveness of targeted attacks.

As SMS phishing attacks increase in sophistication, experts urge organizations and individuals to remain vigilant.

In a hyper-connected world, it only takes one click to compromise a network. Platforms like Devil-Traff serve as a stark reminder that cybersecurity must evolve as quickly as the threats it seeks to combat.

Collect Threat Intelligence with TI Lookup to improve your company’s security - Get 50 Free Request

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Top Ransomware Groups Target Financial Sector, 406 Incidents Revealed

Flashpoint analysts have reported that between April 2024 and April 2025, the financial sector...

Agenda Ransomware Group Enhances Tactics with SmokeLoader and NETXLOADER

The Agenda ransomware group, also known as Qilin, has been reported to intensify its...

SpyCloud Analysis Reveals 94% of Fortune 50 Companies Have Employee Data Exposed in Phishing Attacks

SpyCloud, the leading identity threat protection company, today released an analysis of nearly 6...

PoC Tool Released to Detect Servers Affected by Critical Apache Parquet Vulnerability

F5 Labs has released a new proof-of-concept (PoC) tool designed to help organizations detect...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Top Ransomware Groups Target Financial Sector, 406 Incidents Revealed

Flashpoint analysts have reported that between April 2024 and April 2025, the financial sector...

Agenda Ransomware Group Enhances Tactics with SmokeLoader and NETXLOADER

The Agenda ransomware group, also known as Qilin, has been reported to intensify its...

PoC Tool Released to Detect Servers Affected by Critical Apache Parquet Vulnerability

F5 Labs has released a new proof-of-concept (PoC) tool designed to help organizations detect...