As cited
Copy frozen at (site build).
threat intel
2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services
Google Threat Intelligence Group analyzed a dozen phishing-as-a-service (PhaaS) offerings operating in Chinese-language underground forums, revealing a distinct ecosystem from Russian-language rivals. These services employ advanced techniques including real-time one-time passcode (OTP) interception to bypass multifactor authentication, tokenization of payment data, and delivery via encrypted channels like RCS and iMessage. The Chinese-language PhaaS providers operate more openly than their Russian counterparts and offer ancillary services including money laundering, stolen data sales, and hosting infrastructure.
Why it matters: Organizations and individuals globally face targeted phishing campaigns from Chinese-language threat actors who now have access to mature, purpose-built infrastructure that defeats common security controls including MFA; practitioners should assume attackers can capture OTPs in real-time and focus defenses on anomalous account access patterns and out-of-band verification for sensitive transactions.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services
Google Threat Intelligence Group analyzed a dozen phishing-as-a-service (PhaaS) offerings operating in Chinese-language underground forums, revealing a distinct ecosystem from Russian-language rivals. These services employ advanced techniques including real-time one-time passcode (OTP) interception to bypass multifactor authentication, tokenization of payment data, and delivery via encrypted channels like RCS and iMessage. The Chinese-language PhaaS providers operate more openly than their Russian counterparts and offer ancillary services including money laundering, stolen data sales, and hosting infrastructure.
Why it matters: Organizations and individuals globally face targeted phishing campaigns from Chinese-language threat actors who now have access to mature, purpose-built infrastructure that defeats common security controls including MFA; practitioners should assume attackers can capture OTPs in real-time and focus defenses on anomalous account access patterns and out-of-band verification for sensitive transactions.
- Source published
- First seen by Cybersecurity Tracker