Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Ariana Grande’s “Petal” tracklist released one song at a time on tour

Best Robot Lawn Mower Deal: 45% Off Sunseeker S4 Robot Lawn Mower

BTS’s “Come Over” was chosen as this week’s best new song

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Lucid Phaas attacks 169 targets in 88 countries using Imessage and RCS Smishing
Celebrities

Lucid Phaas attacks 169 targets in 88 countries using Imessage and RCS Smishing

By April 1, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Amazing Farr

A new, sophisticated phishing (PHAAS) platform called Lucid targets 169 entities in 88 countries using smishing messages propagated through Android’s Apple Imessage and Rich Communication Services (RCS).

Lucid’s unique selling point is to weaponize a legitimate communications platform to avoid traditional SMS-based detection mechanisms.

“Its scalable subscription-based model allows cybercriminals to run large-scale phishing campaigns and harvest credit card details for financial fraud,” Swiss cybersecurity company Prodaft said in a technical report shared with Hacker News.

“Lucid leverages Apple Imessage and Android’s RCS technology to bypass traditional SMS spam filters, significantly increasing delivery and success.”

Lucid is credited as the job of a Chinese-speaking hacking crew called Xinxin Group (aka Black Technology), and phishing campaigns primarily target Europe, the UK and the US to steal credit card data and target personally identifiable information (PII).

Cybersecurity

The threats behind this service have, more importantly, developed other PhaAS platforms, such as Lighthouse and Darcula. The latter has the ability to clone the brand’s website to create a phishing version. Lucid’s developers are known as the codenames of threat actors who are also important figures in the Xinxin Group.

All three PHAAS platforms share overlaps of templates, target pools and tactics, hinting at a thriving underground economy where Chinese-speaking actors leverage telegrams to promote Wares on a subscription basis for profit-driven motivation.

Phishing campaigns that rely on these services have been found to provide sensitive information by impersonating postal services, courier companies, fee payment systems, and tax refund agencies, employing persuasive phishing templates to deceive victims.

Large activity powers the backend through a mobile device emulator running on iPhone device farms and Windows systems, sending hundreds of thousands of fraudulent messages containing fake links in a coordinated way. Targeted phone numbers are obtained in a variety of ways, such as data breaches and cybercrime forums.

“Because of the restrictions on clicking on links in Imessage, they employ the ‘Y’ technique to establish two-way communication,” explained Prodaft. “For Google’s RCS filtering, always rotate the send domain/number to avoid pattern recognition.”

iMessage and RCS Smishing

“In the case of IMESSAGE, this creates a temporary Apple ID with the displayed display name, but RCS Exploitation takes advantage of the inconsistency in carrier implementation in verifying senders.”

In addition to providing automated tools to simplify the creation of customizable phishing websites, the page itself incorporates advanced detection and avoidance technologies such as IP blocking, user agent filtering, and time-limited single-use URLs.

Lucid also supports the ability to monitor victim activity and record any interaction with phishing links in real time via panels, allowing customers to extract inputted information. Credit card details submitted by the victim include additional verification steps. The panel is built using the open source Webman PHP framework.

“The Lucid Phaas panel has revealed a highly connected ecosystem as a service run by Chinese-speaking threat actors under the Xinxin group,” the company said.

“The Xinxin Group actively monitors and supports the development of similar PHAAS services, while developing and utilizing these tools and profits from the sale of stolen credit card information.”

Cybersecurity

It is noteworthy that Prodaft’s findings reflect the findings of the Palo Alto Networks Unit 42. It recently called unspecified threat actors to exploit the domain pattern “COM” and registered over 10,000 domains to propagate various SMS phishing scams via Apple Imessage.

The development has now come as Barracuda warned of “large spikes” in PHAAS attacks using Tycoon 2FA, EvilProxy and Sneaky 2FA in early 2025, warning that each service accounts for 89%, 8%, and 3% of all PHAAS incidents, respectively.

“Phishing emails are the gateway for many attacks, from qualification theft to financial fraud to ransomware,” said Direndra Prasad, a security researcher at Barracuda. “Platforms that power phishing as a service are increasingly complex and evasive, and phishing attacks become more and more powerful by traditional security tools to detect and deal damage.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDRPG announces presentation consultants
Next Article Tinder’s new AI-driven game evaluates your flirting skills

Related Posts

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Ariana Grande’s “Petal” tracklist released one song at a time on tour

Best Robot Lawn Mower Deal: 45% Off Sunseeker S4 Robot Lawn Mower

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Trending Posts

Ariana Grande’s “Petal” tracklist released one song at a time on tour

June 15, 2026

BTS’s “Come Over” was chosen as this week’s best new song

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.