2 PhaaS 2 Furious — Chinese-Language Phishing-as-a-Service Ecosystem (UNC5814/Darcula, YY Lai Yu, Lighthouse, Lucid, Smishing Triad)

2 PhaaS 2 Furious (TL-2026-0578), also tracked as 2 PhaaS 2 Furious, is a high-severity phishing campaign, first published 2026-05-25. It is attributed to UNC5814 (China) with high confidence, affects Apple iMessage / Apple Pay / Apple Wallet, maps to 22 MITRE ATT&CK techniques (T1036, T1041, T1056.003), and is covered by 9 detection rules and 40 indicators of compromise.

Key facts for TL-2026-0578

Threat ID
TL-2026-0578
Also known as
2 PhaaS 2 Furious, Chinese-language PhaaS, Smishing Triad ecosystem, Magic Cat, darcula-suite, Panda Shop
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-05-25
Last reviewed
2026-05-25
Attribution
UNC5814
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
financial-services, banking, card-issuers, postal-services, logistics, toll-roads-transit, government, tax-agencies, telecom, retail, ecommerce, consumer-technology
Target regions
North America, Europe, Asia-Pacific, Japan, United Kingdom, Germany, France, Norway, United States, Middle East, United Arab Emirates, Australia
Detection rules
9
Indicators of compromise
40

Malware and tooling in 2 PhaaS 2 Furious

Malware and tooling: Magic Cat, NewBee System, Puppeteer, ZNFC

Google Threat Intelligence Group documented the rapid maturation of a Chinese-language phishing-as-a-service (PhaaS) ecosystem anchored by UNC5814/Darcula (Magic Cat builder), YY Lai Yu, Lighthouse, and Lucid (XinXin group). Operators have shifted from static credential harvesting to real-time OTP/MFA interception via live admin panels, AI-powered cloned phishing pages, mobile-wallet provisioning fraud, RCS/iMessage delivery to bypass SMS carrier filters, and Telegram-based open-air commerce — driving an estimated $15B in annual card-fraud losses across 119+ countries.

How 2 PhaaS 2 Furious works

Google Threat Intelligence Group (GTIG) analyst Jamie Collier published '2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services' on 25 May 2026, providing the most comprehensive public mapping to date of a Chinese-language phishing-as-a-service (PhaaS) ecosystem that has emerged as a peer rival to the historically dominant Russian-speaking phishing underground. The ecosystem comprises roughly a dozen mature offerings advertised openly on Telegram, including Darcula (operated by UNC5814 and powered by the Magic Cat builder), YY Lai Yu (信箱来鱼), Lighthouse, Lucid (XinXin group / Black Technology, developer LARVA-242), Panda Shop (a Smishing Triad rebrand identified by Resecurity in March 2025), and the Oak Tel / Carrie SMS bulk-messaging gateway. Combined activity has produced an estimated $15 billion in annual fraudulent charges (Krebs / Ford Merrill modelling) and 12.7 to 115 million U.S. payment cards compromised between July 2023 and October 2024 alone.

The defining technical shift GTIG documents is a 'fundamental move away from static password harvesting towards real-time interception and tokenization.' When a victim enters credentials and an OTP into a phishing page, the data is rendered instantly on an attacker-controlled administrative panel; the operator triggers the OTP request on their own device simultaneously, allowing them to capture and replay the code seconds before expiry. The captured credential is then used to provision the victim''s card into Apple Pay or Google Wallet on an operator-controlled device — frequently a rack of mass-created accounts. Once tokenized, the card is used for contactless point-of-sale fraud, ATM withdrawals, and high-value online transactions; the waiting period between card theft and use has compressed from 60-90 days to 7-10 days. Operators additionally relay NFC transactions globally via Android tools such as ZNFC ("Ghost Tap"), advertised for $500/month.

Darcula version 3 (darcula-suite 3.0), released April 2025, integrates AI-driven page generation. Operators provide a target URL; the platform uses Puppeteer and browser automation to clone the legitimate site''s HTML, CSS, JavaScript, and visual elements into a unique phishing template — defeating signature-based detection that relied on static template hashes. Installer is fetched from v3.magic-cat.world/install.sh and pages export as portable .cat-page bundles. Lucid and Lighthouse maintain large template libraries (Lighthouse: 600+ templates, 316 brands, 17,500+ domains spanning 74 countries; YY Lai Yu: 400+ templates as of November 2025 across 119 countries with heavy Japan focus). Delivery is shifted from carrier SMS to Apple iMessage and Google RCS because end-to-end encryption denies server-side link inspection; operators use mass-created Apple IDs with spoofed display names and rotate sending domains. Defenders are forced onto on-device protections.

Infrastructure analysis from Palo Alto Unit 42, Resecurity, and Netcraft shows 68.06% of domains registered through Dominet (HK) Limited (Hong Kong), with bulk volume via Alibaba Cloud Computing and Beijing Lanhai Jiye Technology. Favored TLDs include .top, .vip, .icu, .win, .xin, .cc, .cfd, and .world. Infrastructure aggregates on 43,494 unique IPs heavily concentrated in AS13335 (Cloudflare), particularly 104.21.0.0/16, with AliDNS and Cloudflare nameservers handling 45.6% and 34.6% of resolution. Domains are highly disposable: 29.19% are active for two days or less; 82.6% are gone within two weeks. Brand impersonation spans postal services (USPS, Royal Mail, Sagawa, DHL), toll authorities (E-ZPass, SunPass, FasTrak), tax agencies (IRS, UK government, Michigan.gov), banks (Bank of America, Chase, Citibank, JA Bank), card networks (JCB, Visa, Mastercard via co-brands), telecom (AT&T, Vodafone, Du), and consumer tech (Google with 107 sign-in templates alone, Apple, Amazon, Nintendo, Mercari, PayPay).

Attribution is unusually well-established for this segment. Joint reporting by NRK, Mnemonic, Bayerischer Rundfunk, Le Monde, and OSINT Industries identified UNC5814''s primary operator as Yucheng C., 24, of Henan Province, China, operating under handles ''x66'', ''x667788x'', and ''Darcula''. The Lucid developer is tracked as LARVA-242 within the XinXin / Black Technology group. YY Lai Yu management uses handles ''Jeffrey Carrie'' and ''Very casual''. The Smishing Triad acts as a consumer collective stitching multiple kits into industrial-scale campaigns; one Panda Shop actor was observed dispatching up to 2,000,000 smishing messages per day. Google filed a RICO, Lanham Act, and CFAA complaint in the U.S. District Court for the Southern District of New York in November 2025 against 25 unnamed defendants operating Lighthouse, alleging $1B+ in losses and naming over 17,500 domains. Bloomberg reported a parallel civil action against the Darcula group on 17 December 2025. The ecosystem''s ancillary economy spans PII brokerage, VPS rental, money laundering, IMSI catchers, and spamming services — making takedown a defense-in-depth exercise rather than a single-vector cleanup.

MITRE ATT&CK techniques used in TL-2026-0578

Defense Evasion

T1036 Masquerading; T1564 Hide Artifacts; T1684.001 Impersonation

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Credential Access

T1056.003 Input Capture: Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1621 Multi-Factor Authentication Request Generation

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102 Web Service

Collection

T1119 Automated Collection

Initial Access

T1566 Phishing; T1566.002 Phishing: Spearphishing Link; T1566.003 Phishing: Spearphishing via Service

Resource Development

T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1586.002 Compromise Accounts: Email Accounts; T1587.001 Develop Capabilities: Malware; T1588.002 Obtain Capabilities: Tool; T1608.004 Stage Capabilities: Drive-by Target

Impact

T1657 Financial Theft

Affected products and versions in 2 PhaaS 2 Furious

  • Apple — iMessage / Apple Pay / Apple Wallet
    Vulnerable versions: all iOS versions supporting iMessage link delivery and wallet provisioning
  • Google — Android RCS (Google Messages) / Google Wallet
    Vulnerable versions: all Android versions supporting RCS link delivery and Google Wallet provisioning
  • Multiple — Card issuers using SMS/email OTP for mobile-wallet provisioning
    Vulnerable versions: all card issuers relying solely on legacy OTP for wallet enrollment
  • Multiple — Impersonated brands (USPS, Royal Mail, Sagawa, E-ZPass, SunPass, IRS, DMV, Bank of America, Chase, JA Bank, JCB, Apple, Google, Amazon, Nintendo, Mercari, PayPay, JR, plus 300+ others)
    Vulnerable versions: n/a — brand impersonation, not product CVE

Remediation for 2 PhaaS 2 Furious

Patches

  • No software patch — this is an ecosystem-level criminal operation, not a single vulnerability. Mitigation is policy, telemetry, and authentication architecture.

Immediate actions

  • Block known Darcula/Magic Cat/Smishing Triad IOC IPs and domains at perimeter and DNS layer
  • Enable Google Safe Browsing and equivalent on-device URL reputation across managed mobile fleet
  • Hunt proxy and EDR logs for /loadDarcula.js, darcula_call_submit, darcula_call_purchase, /api/can-active, /api/index/config, /api/user/initClient strings
  • Alert card issuers to BIN ranges trending in Smishing Triad telemetry and enable proactive BIN-based wallet-enrollment blocks
  • User awareness blast: never enter card data after clicking a link in SMS/iMessage/RCS; verify postal/toll/tax messages via official apps only

Workarounds

  • Where passkeys unavailable, use authenticator apps with number matching rather than SMS OTP
  • Disable iMessage and RCS link previews on enterprise-managed devices via MDM where feasible
  • Apply CAA records, DMARC/DKIM/SPF alignment, and HSTS preload to reduce lookalike confusion for impersonated brands

Longer-term hardening

  • Roll out FIDO2 hardware-bound passkeys to defeat real-time OTP capture across consumer and workforce accounts
  • Deploy continuous brand-impersonation monitoring via Netcraft, urlscan, DomainTools, with automated takedown workflows for .top, .vip, .icu, .xin, .win, .cc, .cfd registrations
  • Card issuers harden mobile-wallet provisioning OTP messaging: plain-language disclosure that the code enrolls the card into a digital wallet; require step-up verification or biometric
  • Detect wallet-provisioning velocity anomalies (multiple wallet enrolments per card across geographies) and freeze cards automatically
  • Carrier and messaging platform investment in on-device link reputation for end-to-end encrypted RCS/iMessage, plus aggressive throttling of newly-created Apple IDs and Google accounts used for bulk messaging
  • Civil action precedent: replicate Google v. Lighthouse RICO/CFAA model for sustained takedown pressure

Weaknesses (CWE) in 2 PhaaS 2 Furious

CWE-1021, CWE-451, CWE-290, CWE-308

Timeline of 2 PhaaS 2 Furious

Showing the 20 most recent tracked events.

  • XinXin group / Black Technology begins development of Lucid PhaaS (mid-2023 operational start per PRODAFT)
  • First Darcula smishing campaigns hit Norway; Israeli researcher first identifies the Darcula alias in late 2023
  • Palo Alto Unit 42 begins tracking Smishing Triad infrastructure; will catalogue 194,345 FQDNs across 136,933 root domains
  • Mnemonic begins Darcula investigation after a suspicious SMS is delivered to one of its researchers
  • Oak Tel / Carrie SMS bulk SMS gateway domain registered out of Guangdong, China; offers UK consumer messaging at $8.00/1,000
  • Netcraft begins blocking Darcula infrastructure at scale; will accumulate 90,000+ blocked domains and 20,000+ takedowns across 31,000 IPs
  • Smishing Triad expands US-focused USPS and toll-road impersonation campaigns
  • YY Lai Yu (YY来鱼) first advertised on Telegram by management handles Jeffrey Carrie and Very casual
  • End of DOJ-cited 15-month window; 12.7M to 115M U.S. payment cards estimated compromised between July 2023 and October 2024
  • Panda Shop infrastructure registered via Beijing Lanhai Jiye Technology; will be linked to Smishing Triad rebrand
  • Krebs / Ford Merrill publish $15B/yr fraudulent-charge modelling for Smishing Triad ecosystem
  • Resecurity identifies Panda Shop as a Smishing Triad rebrand (moderate confidence)
  • Field Effect publishes XinXin / Lucid analysis confirming 169 entities across 88 countries
  • Darcula announces GenAI integration with darcula-suite v3.0; Puppeteer-driven cloning rendered any brand
  • Google files RICO, Lanham Act, and CFAA lawsuit against 25 unnamed Lighthouse defendants in SDNY; alleges $1B+ losses, 17,500+ domains, 316 brands
  • YY Lai Yu reaches 400+ phishing templates supporting campaigns across 119 countries, with heavy Japan focus
  • Bloomberg reports Google filing a parallel civil action against the Darcula cybercrime group
  • urlscan.io publishes CnDarcula Magic Cat IOC analysis with backend API paths and JavaScript indicators
  • GTIG publishes 2 PhaaS 2 Furious by Jamie Collier — comprehensive ecosystem mapping of Chinese-language PhaaS market
  • As of 2026-05-29, this Chinese-language PhaaS ecosystem (Darcula/UNC5814, Lucid, Lighthouse, Smishing Triad) remains a live, expanding threat per GTIG's 25 May 2026 report, with ~25K domains active at any moment and new 2026 campaigns. Google's RICO suits (Lighthouse Nov 2025, Darcula Dec 2025) disrupted brands but the decentralized ecosystem regenerates faster than prosecution.

Sources cited for 2 PhaaS 2 Furious

Threats related to 2 PhaaS 2 Furious

Detection coverage for TL-2026-0578

As of 2026-05-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0578 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats