2 PhaaS 2 Furious — Chinese-Language Phishing-as-a-Service Ecosystem (UNC5814/Darcula, YY Lai Yu, Lighthouse, Lucid, Smishing Triad)
2 PhaaS 2 Furious (TL-2026-0578), also tracked as 2 PhaaS 2 Furious, is a high-severity phishing campaign, first published 2026-05-25. It is attributed to UNC5814 (China) with high confidence, affects Apple iMessage / Apple Pay / Apple Wallet, maps to 22 MITRE ATT&CK techniques (T1036, T1041, T1056.003), and is covered by 9 detection rules and 40 indicators of compromise.
Key facts for TL-2026-0578
- Threat ID
- TL-2026-0578
- Also known as
- 2 PhaaS 2 Furious, Chinese-language PhaaS, Smishing Triad ecosystem, Magic Cat, darcula-suite, Panda Shop
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-05-25
- Last reviewed
- 2026-05-25
- Attribution
- UNC5814
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- financial-services, banking, card-issuers, postal-services, logistics, toll-roads-transit, government, tax-agencies, telecom, retail, ecommerce, consumer-technology
- Target regions
- North America, Europe, Asia-Pacific, Japan, United Kingdom, Germany, France, Norway, United States, Middle East, United Arab Emirates, Australia
- Detection rules
- 9
- Indicators of compromise
- 40
Malware and tooling in 2 PhaaS 2 Furious
Malware and tooling: Magic Cat, NewBee System, Puppeteer, ZNFC
Google Threat Intelligence Group documented the rapid maturation of a Chinese-language phishing-as-a-service (PhaaS) ecosystem anchored by UNC5814/Darcula (Magic Cat builder), YY Lai Yu, Lighthouse, and Lucid (XinXin group). Operators have shifted from static credential harvesting to real-time OTP/MFA interception via live admin panels, AI-powered cloned phishing pages, mobile-wallet provisioning fraud, RCS/iMessage delivery to bypass SMS carrier filters, and Telegram-based open-air commerce — driving an estimated $15B in annual card-fraud losses across 119+ countries.
How 2 PhaaS 2 Furious works
Google Threat Intelligence Group (GTIG) analyst Jamie Collier published '2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services' on 25 May 2026, providing the most comprehensive public mapping to date of a Chinese-language phishing-as-a-service (PhaaS) ecosystem that has emerged as a peer rival to the historically dominant Russian-speaking phishing underground. The ecosystem comprises roughly a dozen mature offerings advertised openly on Telegram, including Darcula (operated by UNC5814 and powered by the Magic Cat builder), YY Lai Yu (信箱来鱼), Lighthouse, Lucid (XinXin group / Black Technology, developer LARVA-242), Panda Shop (a Smishing Triad rebrand identified by Resecurity in March 2025), and the Oak Tel / Carrie SMS bulk-messaging gateway. Combined activity has produced an estimated $15 billion in annual fraudulent charges (Krebs / Ford Merrill modelling) and 12.7 to 115 million U.S. payment cards compromised between July 2023 and October 2024 alone.
The defining technical shift GTIG documents is a 'fundamental move away from static password harvesting towards real-time interception and tokenization.' When a victim enters credentials and an OTP into a phishing page, the data is rendered instantly on an attacker-controlled administrative panel; the operator triggers the OTP request on their own device simultaneously, allowing them to capture and replay the code seconds before expiry. The captured credential is then used to provision the victim''s card into Apple Pay or Google Wallet on an operator-controlled device — frequently a rack of mass-created accounts. Once tokenized, the card is used for contactless point-of-sale fraud, ATM withdrawals, and high-value online transactions; the waiting period between card theft and use has compressed from 60-90 days to 7-10 days. Operators additionally relay NFC transactions globally via Android tools such as ZNFC ("Ghost Tap"), advertised for $500/month.
Darcula version 3 (darcula-suite 3.0), released April 2025, integrates AI-driven page generation. Operators provide a target URL; the platform uses Puppeteer and browser automation to clone the legitimate site''s HTML, CSS, JavaScript, and visual elements into a unique phishing template — defeating signature-based detection that relied on static template hashes. Installer is fetched from v3.magic-cat.world/install.sh and pages export as portable .cat-page bundles. Lucid and Lighthouse maintain large template libraries (Lighthouse: 600+ templates, 316 brands, 17,500+ domains spanning 74 countries; YY Lai Yu: 400+ templates as of November 2025 across 119 countries with heavy Japan focus). Delivery is shifted from carrier SMS to Apple iMessage and Google RCS because end-to-end encryption denies server-side link inspection; operators use mass-created Apple IDs with spoofed display names and rotate sending domains. Defenders are forced onto on-device protections.
Infrastructure analysis from Palo Alto Unit 42, Resecurity, and Netcraft shows 68.06% of domains registered through Dominet (HK) Limited (Hong Kong), with bulk volume via Alibaba Cloud Computing and Beijing Lanhai Jiye Technology. Favored TLDs include .top, .vip, .icu, .win, .xin, .cc, .cfd, and .world. Infrastructure aggregates on 43,494 unique IPs heavily concentrated in AS13335 (Cloudflare), particularly 104.21.0.0/16, with AliDNS and Cloudflare nameservers handling 45.6% and 34.6% of resolution. Domains are highly disposable: 29.19% are active for two days or less; 82.6% are gone within two weeks. Brand impersonation spans postal services (USPS, Royal Mail, Sagawa, DHL), toll authorities (E-ZPass, SunPass, FasTrak), tax agencies (IRS, UK government, Michigan.gov), banks (Bank of America, Chase, Citibank, JA Bank), card networks (JCB, Visa, Mastercard via co-brands), telecom (AT&T, Vodafone, Du), and consumer tech (Google with 107 sign-in templates alone, Apple, Amazon, Nintendo, Mercari, PayPay).
Attribution is unusually well-established for this segment. Joint reporting by NRK, Mnemonic, Bayerischer Rundfunk, Le Monde, and OSINT Industries identified UNC5814''s primary operator as Yucheng C., 24, of Henan Province, China, operating under handles ''x66'', ''x667788x'', and ''Darcula''. The Lucid developer is tracked as LARVA-242 within the XinXin / Black Technology group. YY Lai Yu management uses handles ''Jeffrey Carrie'' and ''Very casual''. The Smishing Triad acts as a consumer collective stitching multiple kits into industrial-scale campaigns; one Panda Shop actor was observed dispatching up to 2,000,000 smishing messages per day. Google filed a RICO, Lanham Act, and CFAA complaint in the U.S. District Court for the Southern District of New York in November 2025 against 25 unnamed defendants operating Lighthouse, alleging $1B+ in losses and naming over 17,500 domains. Bloomberg reported a parallel civil action against the Darcula group on 17 December 2025. The ecosystem''s ancillary economy spans PII brokerage, VPS rental, money laundering, IMSI catchers, and spamming services — making takedown a defense-in-depth exercise rather than a single-vector cleanup.
MITRE ATT&CK techniques used in TL-2026-0578
Defense Evasion
T1036 Masquerading; T1564 Hide Artifacts; T1684.001 Impersonation
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Credential Access
T1056.003 Input Capture: Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1621 Multi-Factor Authentication Request Generation
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1102 Web Service
Collection
Initial Access
T1566 Phishing; T1566.002 Phishing: Spearphishing Link; T1566.003 Phishing: Spearphishing via Service
Resource Development
T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1586.002 Compromise Accounts: Email Accounts; T1587.001 Develop Capabilities: Malware; T1588.002 Obtain Capabilities: Tool; T1608.004 Stage Capabilities: Drive-by Target
Impact
Affected products and versions in 2 PhaaS 2 Furious
- Apple — iMessage / Apple Pay / Apple Wallet
Vulnerable versions: all iOS versions supporting iMessage link delivery and wallet provisioning - Google — Android RCS (Google Messages) / Google Wallet
Vulnerable versions: all Android versions supporting RCS link delivery and Google Wallet provisioning - Multiple — Card issuers using SMS/email OTP for mobile-wallet provisioning
Vulnerable versions: all card issuers relying solely on legacy OTP for wallet enrollment - Multiple — Impersonated brands (USPS, Royal Mail, Sagawa, E-ZPass, SunPass, IRS, DMV, Bank of America, Chase, JA Bank, JCB, Apple, Google, Amazon, Nintendo, Mercari, PayPay, JR, plus 300+ others)
Vulnerable versions: n/a — brand impersonation, not product CVE
Remediation for 2 PhaaS 2 Furious
Patches
- No software patch — this is an ecosystem-level criminal operation, not a single vulnerability. Mitigation is policy, telemetry, and authentication architecture.
Immediate actions
- Block known Darcula/Magic Cat/Smishing Triad IOC IPs and domains at perimeter and DNS layer
- Enable Google Safe Browsing and equivalent on-device URL reputation across managed mobile fleet
- Hunt proxy and EDR logs for /loadDarcula.js, darcula_call_submit, darcula_call_purchase, /api/can-active, /api/index/config, /api/user/initClient strings
- Alert card issuers to BIN ranges trending in Smishing Triad telemetry and enable proactive BIN-based wallet-enrollment blocks
- User awareness blast: never enter card data after clicking a link in SMS/iMessage/RCS; verify postal/toll/tax messages via official apps only
Workarounds
- Where passkeys unavailable, use authenticator apps with number matching rather than SMS OTP
- Disable iMessage and RCS link previews on enterprise-managed devices via MDM where feasible
- Apply CAA records, DMARC/DKIM/SPF alignment, and HSTS preload to reduce lookalike confusion for impersonated brands
Longer-term hardening
- Roll out FIDO2 hardware-bound passkeys to defeat real-time OTP capture across consumer and workforce accounts
- Deploy continuous brand-impersonation monitoring via Netcraft, urlscan, DomainTools, with automated takedown workflows for .top, .vip, .icu, .xin, .win, .cc, .cfd registrations
- Card issuers harden mobile-wallet provisioning OTP messaging: plain-language disclosure that the code enrolls the card into a digital wallet; require step-up verification or biometric
- Detect wallet-provisioning velocity anomalies (multiple wallet enrolments per card across geographies) and freeze cards automatically
- Carrier and messaging platform investment in on-device link reputation for end-to-end encrypted RCS/iMessage, plus aggressive throttling of newly-created Apple IDs and Google accounts used for bulk messaging
- Civil action precedent: replicate Google v. Lighthouse RICO/CFAA model for sustained takedown pressure
Weaknesses (CWE) in 2 PhaaS 2 Furious
CWE-1021, CWE-451, CWE-290, CWE-308
Timeline of 2 PhaaS 2 Furious
Showing the 20 most recent tracked events.
- XinXin group / Black Technology begins development of Lucid PhaaS (mid-2023 operational start per PRODAFT)
- First Darcula smishing campaigns hit Norway; Israeli researcher first identifies the Darcula alias in late 2023
- Palo Alto Unit 42 begins tracking Smishing Triad infrastructure; will catalogue 194,345 FQDNs across 136,933 root domains
- Mnemonic begins Darcula investigation after a suspicious SMS is delivered to one of its researchers
- Oak Tel / Carrie SMS bulk SMS gateway domain registered out of Guangdong, China; offers UK consumer messaging at $8.00/1,000
- Netcraft begins blocking Darcula infrastructure at scale; will accumulate 90,000+ blocked domains and 20,000+ takedowns across 31,000 IPs
- Smishing Triad expands US-focused USPS and toll-road impersonation campaigns
- YY Lai Yu (YY来鱼) first advertised on Telegram by management handles Jeffrey Carrie and Very casual
- End of DOJ-cited 15-month window; 12.7M to 115M U.S. payment cards estimated compromised between July 2023 and October 2024
- Panda Shop infrastructure registered via Beijing Lanhai Jiye Technology; will be linked to Smishing Triad rebrand
- Krebs / Ford Merrill publish $15B/yr fraudulent-charge modelling for Smishing Triad ecosystem
- Resecurity identifies Panda Shop as a Smishing Triad rebrand (moderate confidence)
- Field Effect publishes XinXin / Lucid analysis confirming 169 entities across 88 countries
- Darcula announces GenAI integration with darcula-suite v3.0; Puppeteer-driven cloning rendered any brand
- Google files RICO, Lanham Act, and CFAA lawsuit against 25 unnamed Lighthouse defendants in SDNY; alleges $1B+ losses, 17,500+ domains, 316 brands
- YY Lai Yu reaches 400+ phishing templates supporting campaigns across 119 countries, with heavy Japan focus
- Bloomberg reports Google filing a parallel civil action against the Darcula cybercrime group
- urlscan.io publishes CnDarcula Magic Cat IOC analysis with backend API paths and JavaScript indicators
- GTIG publishes 2 PhaaS 2 Furious by Jamie Collier — comprehensive ecosystem mapping of Chinese-language PhaaS market
- As of 2026-05-29, this Chinese-language PhaaS ecosystem (Darcula/UNC5814, Lucid, Lighthouse, Smishing Triad) remains a live, expanding threat per GTIG's 25 May 2026 report, with ~25K domains active at any moment and new 2026 campaigns. Google's RICO suits (Lighthouse Nov 2025, Darcula Dec 2025) disrupted brands but the decentralized ecosystem regenerates faster than prosecution.
Sources cited for 2 PhaaS 2 Furious
- 2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services
- Darcula aka. Magic Cat — urlscan.io threat hunting blog
- Google Sues China-Based Hackers Behind $1 Billion Lighthouse Phishing Platform
- The Bleeding Edge of Phishing: darcula-suite 3.0 Enables DIY Phishing of Any Brand
- Darcula-Suite Adds AI: Phishing Kits Now More Accessible
- Darcula and the Magic Cat: How OSINT Unmasked A Phishing Tycoon
- How Phished Data Turns into Apple & Google Wallets
- China-based SMS Phishing Triad Pivots to Banks
- Smishing on a Massive Scale: Panda Shop Chinese Carding Syndicate
- Smishing Triad is Now Targeting Toll Payment Services in a Massive Fraud Campaign Expansion
- The Smishing Deluge: China-Based Campaign Flooding Global Text Messages
- Lucid PhaaS Hits 169 Targets in 88 Countries Using iMessage and RCS Smishing
- XinXin group offers new dreamy PhaaS platform
- Google Looks to Dim Lighthouse Phishing Kit
- Lucid Phishing Tool Exploits Faults in iMessage, RCS
Threats related to 2 PhaaS 2 Furious
- Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)
- Kali365 (K365) PhaaS Expansion — OAuth Device-Code Token Theft Beyond M365 to Okta SSO, AWS, Xerox DocuShare & MAX Messenger (126-Host Cluster, Live C2 Panel)
- TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms
- AccountDumpling — Vietnamese-Linked Facebook Business Hijacking Campaign Abusing Google AppSheet (~30,000 Compromised Accounts)
- Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts (Outsider Enterprise / Google v. Does 1-25)
- 2026 FIFA World Cup Phishing Campaign — 222 Typosquatting Domains, 203 IPs, 4 Operator Clusters (Flare)
Detection coverage for TL-2026-0578
As of 2026-05-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0578 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.