CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

SMS-blaster smishing (Switzerland)

campaign · campaign:sms-blaster-ch-2026 single-source

SMS-blaster smishing establishing itself in Switzerland: portable IMSI-catchers force a 2G downgrade to bypass operator SMS filtering.

Coverage
1
first 2026-05-11 → last 2026-05-11
Latest activity
2026-05-11
SMS-blaster smishing establishing itself in Switzerland, portable IMSI-catchers force 2G downgrade, bypass…
Peak priority
high
1 high
Targets
finance
sectors: finance, public-sector · regions: switzerland
Sources cited
2
2 hosts

Story timeline

  1. 2026-05-11SMS-blaster smishing establishing itself in Switzerland, portable IMSI-catchers force 2G downgrade, bypass operator SMS filtering
    active-threats
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessPhishing

Initial Access TA0001

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-05-11/sms-blaster-smishing-establishing-itself-in-switzerland-port · ATT&CK page ↗

Entries about SMS-blaster smishing (Switzerland) (1)

2026-05-11 · view entry permalink →

HIGH

SMS-blaster smishing establishing itself in Switzerland, portable IMSI-catchers force 2G downgrade, bypass operator SMS filtering

ebas.ch, the Swiss banking-sector and Lucerne University of Applied Sciences (HSLU) e-banking awareness portal; reported on 2026-05-07 that SMS-blaster fraud is establishing itself in Switzerland. A portable device (concealable in a vehicle or backpack) broadcasts as a rogue base station with strong signals that force nearby smartphones within several hundred metres to attach and to downgrade from 4G/5G to 2G. The 2G network lacks mutual authentication between handset and base station, allowing the operator to inject SMS directly into the victim's handset, entirely bypassing the mobile carrier's SMSC, where anti-phishing and anti-spam filters are applied (ebas.ch, 2026-05-07). The lure SMS impersonates authorities, banks or courier services, directing victims to credential-harvesting pages. A brief unexpected RAT downgrade from 4G/5G to 2G on a managed handset, in the absence of corresponding carrier outage signal, is the technical fingerprint of a rogue base station in proximity, although ebas.ch does not report observed victim handset-side telemetry as part of its disclosure.

Why it matters to us: Federal employees and contractors using government-issued or BYOD mobile devices are exposed to the same proximity-targeted lure that no carrier filter can stop. SMS-blaster activity is invisible to enterprise mobile threat-defence (MTD) products that rely on link reputation alone, the lure arrives via SMS, but the device-side signal is a sudden 4G/5G → 2G → 4G/5G transition that some EDR-MDM stacks (Intune mobile telemetry, Jamf Protect) can surface. Suggest disabling 2G on managed Android estates where MDM supports the setting (Android 12+ via setAllowedNetworkTypesForReason / Enterprise restrictions); iOS Lockdown Mode disables 2G but is impractical for routine federal use. Map smishing-lure handling to existing IR runbooks. Mapped to T1566 Phishing at the technique level, the smishing variant delivered via a rogue base station bypasses operator-side SMS filtering by attacking the radio-link delivery channel, not by manipulating data in flight to its intended endpoint. ebas.ch is the only source for the Swiss-localised signal

threat11 May 05:00Zsingle-sourceOpen finding →

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • attack.mitre.org1 (50%)
  • ebas.ch1 (50%)