A sophisticated phishing-as-a-service (PhaaS) platform called Lucid has emerged, targeting 169 entities across 88 countries through Apple iMessage and Android’s Rich Communication Services (RCS). According to cybersecurity firm PRODAFT, Lucid’s effectiveness stems from its use of legitimate communication platforms to bypass traditional SMS security filters.
## Key Features and Operations
Lucid operates on a subscription-based model that enables cybercriminals to conduct large-scale phishing campaigns aimed at harvesting credit card details and personal information. The platform primarily targets users in Europe, the UK, and the US.
The service is attributed to a Chinese-speaking hacking group known as XinXin (also called Black Technology), which has developed other PhaaS platforms including Lighthouse and Darcula. A threat actor codenamed LARVA-242, a key figure in the XinXin group, is identified as Lucid’s developer.
## Technical Infrastructure
The operation uses iPhone device farms and mobile emulators running on Windows systems to send hundreds of thousands of scam messages containing phishing links. To circumvent security measures:
– For iMessage: Attackers use “please reply with Y” techniques to establish two-way communication and create temporary Apple IDs with impersonated display names
– For RCS: They exploit carrier implementation inconsistencies and constantly rotate sending domains/numbers to avoid detection
## Advanced Evasion Techniques
Lucid’s phishing pages incorporate sophisticated anti-detection methods including IP blocking, user-agent filtering, and time-limited single-use URLs. The platform’s control panel, built using the open-source Webman PHP framework, allows real-time monitoring of victim interactions and data extraction.
## Broader Threat Landscape
These findings align with recent research from Palo Alto Networks Unit 42, which identified threat actors using “com-” domain patterns to register over 10,000 domains for SMS phishing via Apple iMessage.
Barracuda researchers predict a “massive spike” in PhaaS attacks in early 2025, with platforms like Tycoon 2FA, EvilProxy, and Sneaky 2FA becoming increasingly complex and evasive, making attacks harder to detect while causing greater damage.
