The Malaysian Communications and Multimedia Commission (MCMC) found a 23 year old local man driving a car equipped with an SMS blaster around Johor Bahru, a Malaysian city bordering Singapore, on July 24. The device transmitted a radio signal that impersonated a mobile provider and sent fraudulent messages containing web links directly to nearby phones.
Initial investigations indicated the syndicate targeted busy public areas during peak hours to maximize the number of messages sent. MCMC did not disclose how many messages had been transmitted or whether any recipients lost money.
The device bypassed a safeguard intended to stop fraudulent links. MCMC requires Malaysian telcos to block SMS messages containing URLs, a measure Commsrisk covered when it was introduced in 2023. The SMS blaster avoided those filters because it delivered messages directly to nearby phones without passing through a legitimate mobile network.



