Continued Phishing Operations Impersonating Canada Post

Aug 28, 2024
phish sms canadapost


Canada Post is an ongoing target for phishing operations. In this case, the SMS message states that the recipient's package is being held. The domain used contains the text "canadapost" in order to appear legitimate. The URL in the SMS is not hyperlinked by default, so the message encourages recipients to respond with a "Y" in order to make the link clickable. Clicking the link takes the visitor to a fake website where they are prompted to enter their information. 

Canada Post has some resources available to help identify these types of messages.

IOCs

canadapost-postewcanada[.]top

107.172.201[.]26

[ IOC Details]