Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Why researchers are developing robots that look and act like bats

Data centers currently attract more investment than finding new sources of oil supply

Google sues China-based hackers behind $1 billion Lighthouse phishing platform

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Google sues China-based hackers behind $1 billion Lighthouse phishing platform
Identity

Google sues China-based hackers behind $1 billion Lighthouse phishing platform

userBy userNovember 12, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 12, 2025Ravi LakshmananCybercrime/Malware

lighthouse fishing platform

Google has filed a civil lawsuit in the U.S. District Court for the Southern District of New York (SDNY) against China-based hackers behind a massive phishing-as-a-service (PhaaS) platform called Lighthouse that has captivated more than 1 million users in 120 countries.

PhaaS kits are used to run large-scale SMS phishing attacks that exploit trusted brands like E-ZPass and USPS, using decoys related to fake tolls and package deliveries to entice people to click on links and steal people’s financial information. Although the scam itself is very simple, the scale of the industry has allowed more than $1 billion to be illegally made over the past three years.

“They are exploiting the reputation of Google and other brands by illegally displaying our trademarks and services on deceptive websites,” said Halima Delaine Prado, Google’s general counsel. “We discovered at least 107 website templates featuring Google branding on the sign-in screen that were specifically designed to trick people into believing the site was legitimate.”

DFIR retainer service

The company said it is taking legal action to dismantle its underlying infrastructure under the Fraudster Act, the Lanham Act, and the Computer Fraud and Abuse Act.

Lighthouse, along with other PhaaS platforms such as Darcula and Lucid, is part of an interconnected cybercrime ecosystem based in China that is known to send thousands of smishing messages to users inside and outside the United States via the RCS feature of Apple iMessage and Google Messages with the intent of stealing sensitive data. These kits are used by the Smishing Syndicate, tracked as the Smishing Triad.

In a report published in September, Netcraft revealed that Lighthouse and Lucid were linked to more than 17,500 phishing domains targeting 316 brands in 74 countries. Phishing template licenses associated with Lighthouse range from $88 for a week to $1,588 for an annual subscription.

“Although Lighthouse operates independently from the XinXin Group, its collaboration with Lucid in terms of infrastructure and targeting patterns highlights broader trends of collaboration and innovation within the PhaaS ecosystem,” Swiss cybersecurity firm PRODAFT said in a report released in April.

CIS build kit

It is estimated that Chinese smishing syndicates may have compromised between 12.7 million and 115 million payment cards in the United States alone between July 2023 and October 2024. In recent years, Chinese cybercrime groups have also evolved, developing new tools like Ghost Tap, which adds stolen card details to digital wallets on iPhone and Android phones.

Just last month, Palo Alto Networks Unit 42 announced that since January 1, 2024, the attackers behind the Smishing Triad have used over 194,000 malicious domains to imitate a wide range of services, including banks, cryptocurrency exchanges, postal and delivery services, law enforcement, state-owned enterprises, and electronic toll systems.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleAmazon discovers zero-day flaw in attacks exploiting Cisco ISE and Citrix NetScaler
Next Article Data centers currently attract more investment than finding new sources of oil supply
user
  • Website

Related Posts

Amazon discovers zero-day flaw in attacks exploiting Cisco ISE and Citrix NetScaler

November 12, 2025

[Webinar] See how leading security teams use DASR to reduce attack surface exposure

November 12, 2025

WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

November 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Why researchers are developing robots that look and act like bats

Data centers currently attract more investment than finding new sources of oil supply

Google sues China-based hackers behind $1 billion Lighthouse phishing platform

Amazon discovers zero-day flaw in attacks exploiting Cisco ISE and Citrix NetScaler

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.