A widespread text-message phishing campaign impersonates T-Mobile, tricking customers into visiting fraudulent reward-redemption pages. The messages claim loyalty points are about to expire, turning a routine reminder into a trap for login details, personal data, payment information, and verification codes. It spreads through rapid variation: attackers change minor details in each message, allowing the same core deception to be sent at scale while evading basic message-matching defenses.

Malwarebytes analysts identified more than 1,000 closely related templates, including 199 highly similar messages. Malwarebytes revealed in a report shared with ZeroOwl (ZeroOwl) that the campaign employs false point balances, urgent deadlines, and rotating links to trick recipients into acting before they verify the claim.

Attackers switch greetings, subject lines, balances, and dates, while maintaining the central claim: valuable points will be lost unless the recipient follows the link immediately. Instead, they should independently open the provider’s official app or enter its known website address in a browser, then check whether any genuine account notice appears there. Indicators of Compromise (IoCs): - Domain: t-mobile.biktpw[.

]top - Domain: t-mobile.cugbjl[. ]top - Domain: t-mobile.cymfjd[. ]top - Domain: t-mobile.gdikxv[. ]top - Domain: t-mobile.hdzcnb[.

]top - Domain: t-mobile.koxetp[. ]top - Domain: t-mobile.nxdcfp[. ]top - Domain: t-mobile.pkrbai[. ]top - Domain: t-mobile.qfrhkt[.

]top - Domain: t-mobile.qscizj[. ]top - Domain: t-mobile.tmfncb[. ]top - Domain: t-mobile.vmnqsu[. ]top Securely integrate threat intelligence into your SOC using platforms like MISP, VirusTotal, or SIEM.