Two major phishing-as-a-service (PhaaS) platforms, Lighthouse and Lucid, have orchestrated a massive cybercrime operation targeting more than 17,500 phishing domains across 316 brands in 74 countries, according to a new Netcraft report.
## The Rise of Phishing-as-a-Service
PhaaS platforms have experienced significant growth recently, operating on a subscription model where cybercriminals pay monthly fees for ready-made phishing software. These services come equipped with pre-installed templates that impersonate hundreds of legitimate brands worldwide, making sophisticated phishing attacks accessible to less technical criminals.
## Key Players and Operations
**Lucid Platform**: First identified by Swiss cybersecurity firm PRODAFT in April 2024, Lucid is operated by the Chinese-speaking XinXin group. The platform specializes in sending phishing messages through Apple iMessage and Android’s Rich Communication Services (RCS). Netcraft detected phishing URLs targeting 164 brands across 63 countries through this platform.
**Lighthouse Platform**: Operating independently but showing alignment with Lucid’s infrastructure, Lighthouse targets 204 brands in 50 countries. The service offers subscription plans ranging from $88 weekly to $1,588 annually and boasts templates for over 200 platforms globally.
## Sophisticated Targeting Methods
Both platforms employ advanced filtering techniques to ensure only intended victims access phishing sites. They use criteria such as:
– Specific mobile user-agents
– Proxy country requirements
– Custom-configured access paths
When non-targeted users visit these URLs, they’re redirected to generic fake storefronts instead of the actual phishing content.
## Evolving Communication Channels
The cybercrime landscape is shifting away from platforms like Telegram for data transmission. Instead, criminals are returning to email channels, with Netcraft reporting a 25% increase in email-based credential harvesting within a single month. This shift occurs because email’s federated nature makes takedowns more difficult, requiring individual reporting of each address or SMTP relay.
## New Attack Techniques
**Homoglyph Attacks**: Cybercriminals are exploiting the Japanese Hiragana character “ん” to create lookalike domains that appear nearly identical to legitimate websites. Over 600 fake domains using this technique have been identified, primarily targeting cryptocurrency users by impersonating popular wallet extensions like MetaMask, Coinbase, and Phantom.
**Task-Based Scams**: Fraudsters are impersonating major American brands including Delta Airlines, AMC Theatres, and Universal Studios to promote money-making schemes. These scams require victims to deposit at least $100 in cryptocurrency to participate in fake job opportunities like flight booking agent roles.
## Industry Impact
The targeted industries span multiple sectors:
– Financial institutions
– Government agencies
– Postal services
– Toll companies
– Cryptocurrency platforms
## Expert Analysis
“Lucid and Lighthouse demonstrate how rapidly these platforms can evolve and how challenging they are to disrupt,” noted Netcraft researcher Harry Everett. The collaboration between different PhaaS operators highlights the growing sophistication and innovation within the cybercrime ecosystem.
These developments underscore the need for enhanced cybersecurity awareness and protective measures as phishing operations become increasingly professional and scalable through service-based models.
