Smishing (SMS phishing)

Bait delivered by text message, with configurable sender profiles and attention to LGPD consent.

What smishing is

Smishing is phishing over SMS. The channel has extremely high open rates, and the user is usually on their phone with their guard down, which makes it a realistic vector to simulate.

In qlture, smishing is a channel within the phishing module. It’s opt-in: it only shows up in the interface if an SMS sender is configured.

Smishing (SMS) screen in the qlture dashboard
Smishing → Campaigns: only employees with a registered phone number receive it.

SMS involves a per-message cost, employees' phone numbers and consent. Treat your phone-number base and consent as the responsibility of your internal process (LGPD).

Prerequisites

  • Targets’ phone numbers. The campaign only sends to those with a valid phone number in E.164 format (e.g. +5511999998888). Targets without a phone number are skipped. Populate phone numbers via import or SCIM.
  • An SMS sender. Configured per profile (see below) or via system environment variables.

If no sender is available, the SMS channel simply does not appear in the vector selector.

SMS senders

Just like SMTP profiles for email, you register SMS sender profiles under Phishing → SMS senders. Each profile picks a provider:

Provider Note
AWS SNS Reuses the AWS credentials already used on the platform
Twilio Twilio account and credentials
Generic HTTP For Zenvia, Comtele, Infobip etc., via a body template with {{to}} and {{text}}

Profile secrets are encrypted and never returned by the API. The campaign points to a smsSenderId; if left blank, it uses the system default sender (configured per environment).

SMS senders in the qlture dashboard
Smishing → Senders: profiles per provider (AWS SNS, Twilio or generic HTTP).

Composing the bait

When you pick the SMS (smishing) vector, step 1 swaps the email fields for the SMS composer:

qlture: we detected an unusual sign-in. Confirm at {{link}}

The composer includes:

  • A character and segment counter (SMS is billed per segment).
  • A warning if the trackable {{link}} is missing.
  • A visible LGPD consent note.
  • A preview in an SMS bubble.

The {{link}} is the individual trackable link. Clicks and landing reuse the same mechanism as the other channels.

Tracking differences

SMS is leaner than email:

  • No open pixel — there’s no way to measure “opened” over SMS.
  • No report button — it doesn’t fit the format.
  • Click and landing work normally, per target.

Deliverability in Brazil

Delivering SMS to Brazil (especially via AWS SNS) requires sender registration and compliance with Anatel rules on the provider’s side. That’s operational configuration in your provider account, outside qlture.


Quishing (QR Code phishing)
Senders, templates and pages