CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 311

As cited

Copy frozen at (site build).

threat intel

2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services

Google Threat Intelligence Group analyzed a dozen phishing-as-a-service (PhaaS) offerings operating in Chinese-language underground forums, revealing a distinct ecosystem from Russian-language rivals. These services employ advanced techniques including real-time one-time passcode (OTP) interception to bypass multifactor authentication, tokenization of payment data, and delivery via encrypted channels like RCS and iMessage. The Chinese-language PhaaS providers operate more openly than their Russian counterparts and offer ancillary services including money laundering, stolen data sales, and hosting infrastructure.

Why it matters: Organizations and individuals globally face targeted phishing campaigns from Chinese-language threat actors who now have access to mature, purpose-built infrastructure that defeats common security controls including MFA; practitioners should assume attackers can capture OTPs in real-time and focus defenses on anomalous account access patterns and out-of-band verification for sensitive transactions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services

Google Threat Intelligence Group analyzed a dozen phishing-as-a-service (PhaaS) offerings operating in Chinese-language underground forums, revealing a distinct ecosystem from Russian-language rivals. These services employ advanced techniques including real-time one-time passcode (OTP) interception to bypass multifactor authentication, tokenization of payment data, and delivery via encrypted channels like RCS and iMessage. The Chinese-language PhaaS providers operate more openly than their Russian counterparts and offer ancillary services including money laundering, stolen data sales, and hosting infrastructure.

Why it matters: Organizations and individuals globally face targeted phishing campaigns from Chinese-language threat actors who now have access to mature, purpose-built infrastructure that defeats common security controls including MFA; practitioners should assume attackers can capture OTPs in real-time and focus defenses on anomalous account access patterns and out-of-band verification for sensitive transactions.

VendorsAppleGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary