2 PhaaS 2 Furious — Chinese-Language Phishing-as-a-Service Ecosystem (UNC5814/Darcula, YY Lai Yu, Lighthouse, Lucid, Smishing Triad) — Threadlinqs Intelligence
As of 2026-05-30, 2 PhaaS 2 Furious — Chinese-Language Phishing-as-a-Service Ecosystem (UNC5814/Darcula, YY Lai Yu, Lighthouse, Lucid, Smishing Triad) is a high-severity phishing threat attributed to UNC5814 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 40 indicators of compromise.
Threat ID: TL-2026-0578 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: UNC5814 · China · FINANCIAL
Google Threat Intelligence Group documented the rapid maturation of a Chinese-language phishing-as-a-service (PhaaS) ecosystem anchored by UNC5814/Darcula (Magic Cat builder), YY Lai Yu, Lighthouse,
Google Threat Intelligence Group (GTIG) analyst Jamie Collier published '2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services' on 25 May 2026, providing the most comprehensive public mapping to date of a Chinese-language phishing-as-a-service (PhaaS) ecosystem that has emerged as a peer rival to the historically dominant Russian-speaking phishing underground. The ecosystem comprises roughly a dozen mature offerings advertised openly on Telegram, including Darcula (operated by UNC5814 and powered by the Magic Cat builder), YY Lai Yu (信箱来鱼), Lighthouse, Lucid (XinXin group / Black Technology, developer LARVA-242), Panda Shop (a Smishing Triad rebrand identified by Resecurity in March 2025), and the Oak Tel / Carrie SMS bulk-messaging gateway. Combined activity has produced an estimated $15 billion in annual fraudulent charges (Krebs / Ford Merrill modelling) and 12.7 to 115 million U.S. payment cards compromised between July 2023 and October 2024 alone.
The defining technical shift GTIG documents is a 'fundamental move away from static password harvesting towards real-time interception and tokenization.' When a victim enters credentials and an OTP into a phishing page, the data is rendered instantly on an attacker-controlled administrative panel; the operator triggers the OTP request on their own device simultaneously, allowing them to capture and replay the code seconds before expiry. The captured credential is then used to provision the victim''s card into Apple Pay or Google Wallet on an operator-controlled device — frequently a rack of mass-created accounts. Once tokenized, the card is used for contactless point-of-sale fraud, ATM withdrawals, and high-value online transactions; the waiting period between card theft and use has compressed from 60-90 days to 7-10 days. Operators additionally relay NFC transactions globally via Android tools such as ZNFC ("Ghost Tap"), advertised for $500/month.
Darcula version 3 (darcula-suite 3.0), released April 2025, integrates AI-driven page generation. Operators provide a target URL; the platform uses Puppeteer and browser automation to clone the legitimate site''s HTML, CSS, JavaScript, and visual elements into a unique phishing template — defeating signature-based detection that relied on static template hashes. Installer is fetched from v3.magic-cat.world/install.sh and pages export as portable .cat-page bundles. Lucid and Lighthouse maintain large template libraries (Lighthouse: 600+ templates, 316 brands, 17,500+ domains spanning 74 countries; YY Lai Yu: 400+ templates as of November 2025 across 119 countries with heavy Japan focus). Delivery is shifted from carrier SMS to Apple iMessage and Google RCS because end-to-end encryption denies server-side link inspection; operators use mass-created Apple IDs with spoofed display names and rotate sending domains. Defenders are forced onto on-device protections.
Infrastructure analysis from Palo Alto Unit 42, Resecurity, and Netcraft shows 68.06% of domains registered through Dominet (HK) Limited (Hong Kong), with bulk volume via Alibaba Cloud Computing and Beijing Lanhai Jiye Technology. Favored TLDs include .top, .vip, .icu, .win, .xin, .cc, .cfd, and .world. Infrastructure aggregates on 43,494 unique IPs heavily concentrated in AS13335 (Cloudflare), particularly 104.21.0.0/16, with AliDNS and Cloudflare nameservers handling 45.6% and 34.6% of resolution. Domains are highly disposable: 29.19% are active for two days or less; 82.6% are gone within two weeks. Brand impersonation spans postal services (USPS, Royal Mail, Sagawa, DHL), toll authorities (E-ZPass, SunPass, FasTrak), tax agencies (IRS, UK government, Michigan.gov), banks (Bank of America, Chase, Citibank, JA Bank), card networks (JCB, Visa, Mastercard via co-brands), telecom (AT&T, Vodafone, Du), and consumer tech (Google with 107 sign-in templates alone, Apple, Amazon, Nintendo, Mercari, PayPay).
Attribution is unusually well-established for this segment.
Weaknesses (CWE)
CWE-1021, CWE-451, CWE-290, CWE-308
Target sectors: financial-services, banking, card-issuers, postal-services, logistics, toll-roads-transit, government, tax-agencies, telecom, retail, ecommerce, consumer-technology
Target regions: North America, Europe, Asia-Pacific, Japan, United Kingdom, Germany, France, Norway, United States, Middle East, United Arab Emirates, Australia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 40 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1583.001, T1583.006, T1586.002, T1587.001, T1588.002, T1608.004, T1566, T1566.002, T1566.003