T1496.003sub-technique of T1496 Resource Hijacking
SMS Pumping
SaaSnothing on this site yetT1496.003 on attack.mitre.org
Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability. SMS pumping is a type of telecommunications fraud whereby a threat actor first obtains a set of phone numbers from a telecommunications provider, then leverages a victim’s messaging infrastructure to send large amounts of SMS messages to numbers in that set.
If this is happening now
Checklists and playbooks to open while the alert is still live.
Playbook for this stage
Ransomware, suspected or confirmed
Files renamed or unreadable, a ransom note, or backup deletion commands seen.
how MITRE says to see it
Detection Strategy for Resource Hijacking: SMS Pumping via SaaS Application Logs
- Automated and repetitive triggering of SMS messages through OTP/account verification fields on SaaS platforms, leveraging background messaging APIs such as Twilio, AWS SNS, or Amazon Cognito to generate traffic toward attacker-controlled numbers.
what reduces it
- M1013 Application Developer Guidance. Consider implementing CAPTCHA protection on forms that send messages via SMS.