Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames behind a WebSocket-based backend that streamed victims' card data in real time and included an operator kill-switch, a concrete technical case of the package-delivery smishing wave USPS itself had flagged as rising in June 2025.
Reviewed by the Social Engineering Examples team.
Censys security researchers investigated a live SMS phishing ("smishing") operation impersonating USPS package-delivery notifications. Starting from a single reported lure hostname/IP, they used passive/historical DNS data (a Censys DNS snapshot dated 2026-05-20) to pivot outward and reconstruct a much larger rotating infrastructure: 682 unique lookalike hostnames across five naming patterns, all pointing back to a small hosting cluster on Tencent Cloud. Beyond mapping the domains, Censys reverse-engineered the kit's client-side behavior and found it exfiltrated victims' payment card data in real time over a WebSocket connection, streaming keystrokes as they were typed before form submission, with a backend that ran server-side BIN lookups and could remotely trigger a kill-switch to bounce a given victim to the real usps.com. Censys also identified a linked UPS-themed sibling campaign on separate (Java/Spring Boot) backend infrastructure, tied to the USPS campaign via a shared internal cookie/theme string ("us_post_ups"). The findings were published as a Censys technical blog post on 2026-06-12. Separately (a year earlier), USPS and the U.S. Postal Inspection Service held a June 12, 2025 press briefing in Tampa, Florida, warning that package-themed phishing, smishing, and "brushing" scams were on the rise and reaffirming that USPS never sends unsolicited texts/emails with links requesting personal or payment information; that briefing also reported broader Project Safe Delivery enforcement results (2,800+ arrests, 27% reduction in carrier robberies) unrelated to this specific kit.
Victims received an SMS ("smish") impersonating USPS (or, in a sibling campaign, UPS) claiming a package required action, with a link to a lookalike domain. The landing page replicated USPS's real production web assets (fonts, CSS, images) verbatim and even fired USPS's own live analytics tags, making the fake page visually and telemetrically indistinguishable from the real site. Instead of harvesting data only on form submission, the phishing page opened a live WebSocket connection to an operator-controlled backend and streamed the victim's card number and other input keystroke-by-keystroke as they typed, before the form was even submitted (Censys logged 279 WebSocket frames across seven captured live sessions). The backend performed a server-side BIN (bank identification number) lookup on the card data in real time. Operators could also push a kill-switch flag (referred to in the kit as "isBlock") that would redirect a given victim session to the legitimate www.usps.com, likely used to evade investigators or burn a session once data was captured or a visitor was flagged as suspicious (e.g., a researcher or bot). Rather than one throwaway domain, the infrastructure rotated across a cluster Censys mapped via passive/historical DNS to 682 unique lookalike hostnames, breaking down as roughly 334 "*.life" domains, 250 "informed.deliwek*.shop" names, 78 "usps.xupq*.one" names, 17 "deliwek*.shop" names, and 3 "xupq*.one" apexes. A related UPS-themed campaign ran on a separate Java/Spring Boot backend but shared an internal cookie/theme identifier ("us_post_ups") linking the two brand-impersonation operations to the same underlying actor/toolset. The cluster was hosted on Tencent Cloud, spanning two IP prefixes (43.157.128.0/18 and 43.173.64.0/18).
The lure: an SMS text claiming a USPS or UPS package required customer action (e.g., a redelivery fee, address confirmation, or "awaiting action") with a link to what looked exactly like the real carrier's website: same fonts, CSS, images, and even the same live analytics tracking as usps.com. The tell, per USPS's own repeated public guidance (reiterated at the June 12, 2025 Tampa press briefing): USPS and the Postal Inspection Service never send unsolicited text messages or emails containing tracking numbers or links asking for personal information or payment; any such message is fraudulent regardless of how convincing the linked page looks. Technically, the giveaway invisible to victims but visible to researchers was the underlying domain-rotation pattern (hundreds of near-identical disposable hostnames resolving to a small, stable IP cluster) and the live WebSocket connection silently streaming keystrokes to a backend before any "submit" action, behavior a legitimate USPS/UPS payment page would never exhibit.
Censys publicly disclosed the technical anatomy of the kit (domain infrastructure, WebSocket exfiltration mechanism, kill-switch, hosting details, and the linked UPS sibling campaign) on June 12, 2026, enabling defenders, registrars, and hosting providers to identify and take down related infrastructure by pivoting on the shared fingerprints (hosting ASN, cookie/theme strings, DNS rotation pattern) rather than one domain at a time. No arrest, indictment, or other law-enforcement action tied specifically to this kit was found in the primary sources reviewed. USPS/USPIS's own program (Project Safe Delivery, launched May 2023) reported broader results as of June 2025 (2,800+ arrests related to mail theft and related crimes and a 27% YoY reduction in letter-carrier robberies), but those figures are program-wide and not attributed to this particular smishing/skimming cluster.
This case is a documented, technically detailed illustration of how modern smishing operations have industrialized: rather than a single throwaway phishing link, defenders are facing large, actively rotated domain fleets (682 hostnames in this instance) sitting behind shared backend infrastructure, engineered for real-time data theft (WebSocket streaming of card data mid-keystroke) and equipped with operational security features (a remote kill-switch, cloned brand assets down to the analytics tags) that make both victim detection and takedown harder. It also demonstrates the value of passive DNS as a defensive/investigative tool: a single reported lure expanded, via historical resolution data, into visibility over an entire criminal infrastructure cluster and a linked second-brand campaign. For an educational audience, the case underscores that USPS/UPS "package awaiting action" texts remain one of the most common and effective smishing lures precisely because almost everyone expects packages, and that visual fidelity to a real brand's site (even reusing its actual static assets and analytics) is not a reliable indicator of legitimacy; the only reliable rule is that carriers do not send unsolicited texts/emails with action-required links.
Recommended/observed defenses drawn from the sources: (1) passive-DNS-based threat hunting: pivoting from one seed hostname/IP to historical resolution data to expose entire rotating infrastructures rather than chasing individual disposable domains one at a time; (2) treating unsolicited "package awaiting action" texts with links as inherently suspicious: USPS and USPIS state flatly that USPS never sends unsolicited texts/emails with tracking links asking for personal or payment information, and directs recipients to forward suspicious texts to 7726 (SPAM) and report at USPIS.gov; (3) domain/infrastructure-level detection: clustering on hosting ASN, TLS certificate reuse, and cookie/theme fingerprints (e.g., the shared "us_post_ups" theme string) can catch sibling campaigns even when surface branding differs; (4) awareness that a convincing phishing page can serve a brand's real static assets (fonts, CSS, images) and even fire the real brand's analytics tags, so visual fidelity alone is not a valid trust signal; (5) card issuers/banks watching for real-time BIN-lookup-driven skimming patterns rather than assuming card data theft only happens via bulk breach dumps.
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
A Pune CFO wired Rs 56 lakh after a Microsoft Teams message impersonating her Italian CEO's name and photo demanded…