🇲🇾💻 Tech

Scammers pivot to RCS and iMessage as SMS hyperlink restrictions tighten

Cybercriminals are bypassing tighter SMS security measures by shifting phishing tactics to encrypted and advanced messaging platforms.

PETALING JAYA, Aug 21 — Online scammers in Malaysia are increasingly pivoting away from traditional SMS to Rich Communication Services (RCS) and iMessage to distribute phishing links, following the implementation of stricter hyperlink restrictions on standard text messages.

According to the original publisher, the Malaysian Communications and Multimedia Commission (MCMC) has identified this tactical shift as a direct response to recent regulatory efforts aimed at curbing the proliferation of fraudulent links in SMS. By moving to messaging services like RCS and iMessage, perpetrators are attempting to circumvent the "no-hyperlink" policy that local telecommunications companies have been mandated to enforce for standard SMS to protect consumers from financial fraud.

The mechanics of this new wave of attacks exploit the inherent features of modern messaging platforms. While RCS and iMessage offer end-to-end encryption and a richer user experience, they also allow for the seamless integration of external web links that appear more legitimate to the average user. Unlike standard SMS, which has become heavily filtered by telco-level firewalls, these platforms operate within ecosystems that are currently more difficult for traditional regulatory blocks to monitor in real-time.

Security analysts note that this migration is likely a reactive move, as scammers find their previous primary channel of attack—bulk SMS—under constant scrutiny. The move to RCS is particularly notable as it becomes the default communication standard on many modern smartphones, effectively providing a new, high-trust environment for bad actors to operate in without triggering the typical "spam" warnings that users have become accustomed to on SMS.

For Malaysian consumers, this shift signifies a change in the frontlines of digital safety. As the economy maintains a robust growth rate of 6.0% year-on-year, the digital marketplace remains highly active, making users prime targets for phishing attempts that mimic legitimate banking or e-commerce communications. With inflation holding steady at 1.8%, consumers are more sensitive to financial fluctuations, and any compromise of personal banking details via these platforms poses a significant risk to household stability and personal savings.

For the local workforce and small-to-medium enterprises (SMEs), this development mandates a higher level of digital vigilance. Workers who rely on mobile communications for business operations may no longer be able to rely solely on telco-side link blocking. This suggests that the responsibility for identifying malicious content is shifting more heavily onto the individual user and the device settings themselves. If you receive an unexpected message containing a link—even if it arrives via an app that feels more "premium" than an SMS—the risk of a phishing attempt remains high.

This development occurs against a backdrop of ongoing efforts by the MCMC to sanitize the digital communication landscape. Previous efforts, such as the mandated removal of hyperlinks in person-to-person SMS, were successful in reducing the sheer volume of high-risk messages reaching the public. However, the rapid evolution of these scams underscores the "cat-and-mouse" nature of cybercrime in Malaysia’s increasingly connected digital economy.

Industry observers will be watching to see if the MCMC or the messaging service providers themselves will implement new detection layers specifically tailored to identify malicious URLs within RCS and iMessage threads. While current figures show a stable unemployment rate of 3.0%, the digital economy remains a core pillar of national development, and maintaining trust in mobile communication is essential to sustain that growth.

Whether further regulatory intervention will be required to force platform-level filters on RCS and iMessage, or if public awareness campaigns will be the primary defensive measure, remains unconfirmed at this stage. Officials have not disclosed specific data regarding the volume of incidents intercepted on these newer platforms compared to traditional SMS.

Source

Originally reported by Malay Mail. Read the original report →

Join the conversation

We post stories like this all day on Threads. Discuss this story on Threads →

More in Tech