SMS PVA Services’ Use of Infected Android Phones Reveals Flaws in SMS Verification

There has been an increase in short message service (SMS) phone-verified account (PVA) services in the last two years. SMS PVA services provide alternative mobile numbers that customers can use to register for online services and platforms. These types of services help circumvent the SMS verification mechanisms widely used by online platforms and services to authenticate new accounts. Malicious actors can register disposable accounts in bulk or create phone-verified accounts for criminal activities.

In the following sections, Trend Micro researchers share the results of our investigation into the operations of a SMS PVA provider that uses the site smspva[.]net. They provide further details in their research, “SMS PVA: An Underground Service Enabling Threat Actors to Register Bulk Fake Accounts.”

Read more…
Source: Trend Micro