Google Threat Intelligence Group analyzed a growing Chinese-language phishing-as-a-service ecosystem that uses RCS and iMessage, real-time OTP interception, and digital wallet tokenization to bypass MFA and monetize stolen payment data. The report highlights mature services such as Darcula and YY Lai Yu, extensive localization for global targets like Japan, and the use of AI automation to generate unique phishing pages and evade detection. #Darcula #YYLaiYu #UNC5814 #RCS #iMessage #FIDO2 #WebAuthn
Keypoints
- Chinese-language PhaaS offerings are rapidly expanding and now form a mature underground ecosystem distinct from Russian-speaking operations.
- These services increasingly target the general public and mostly impersonate non-Chinese organizations, with a strong focus on overseas victims.
- Attackers have shifted from static credential theft to real-time interception of credentials and OTPs to defeat MFA.
- RCS and iMessage are heavily used because encrypted delivery makes malicious links harder to filter than traditional SMS.
- Stolen card data is often monetized through digital wallet provisioning and tokenization, enabling high-value transactions and ATM withdrawals.
- AI-powered page generation and browser automation let operators create unique phishing pages at scale and reduce the effectiveness of signature-based detection.
- YY Lai Yu and Darcula illustrate the sophistication of the ecosystem, including localization, anti-bot checks, and broad international targeting.
MITRE Techniques
- [T1566.002 ] Phishing: Spearphishing Link – Victims receive malicious links through encrypted messaging to lure them into entering credentials and OTPs (‘messages also contain more extensive engagement features… ideal for social engineering operations’ and ‘send encrypted messages in bulk’).
- [T1110 ] Brute Force – OTPs are captured in real time and used immediately to bypass authentication controls (‘the victim enters the code into the phishing page, and the attacker captures it seconds before it expires’).
- [T1056.004 ] Input Capture: Credential API Hooking / Web Session Interception – Live administrative panels display entered credentials instantly for attacker use (‘the data is displayed instantly on an administrative panel’).
- [T1556 ] Modify Authentication Process – Attackers use synchronized OTP requests and live interaction to defeat MFA (‘As the victim is prompted for an OTP, an attacker simultaneously triggers that same OTP request on their own device’).
- [T1027 ] Obfuscated Files or Information – Encrypted delivery channels and unique AI-generated pages make filtering and signature detection harder (‘protocols that use end-to-end encryption make it difficult’ and ‘each phishing page is unique’).
- [T1585 ] Establish Accounts – Operators create and manage new users and domains through the admin panel (‘panel administrators can create new operator users and assign them their permissions’ and ‘register and manage new domains’).
- [T1608.005 ] Stage Capabilities: Upload Malware – Phishing infrastructure is provisioned with hosted domains and pages for delivery (‘domains that can be purchased within the administration panel’).
- [T1222.001 ] File and Directory Permissions Modification – Anti-bot verification forces manual interaction before access, hindering automation (‘requiring a manual click to proceed’).
Indicators of Compromise
- [Threat Actor / Platform Names ] PhaaS ecosystem and linked operators – Darcula, YY Lai Yu (YY来鱼), UNC5814
- [Messaging Platforms ] delivery and coordination channels – RCS, iMessage, Telegram
- [Phishing Brands / Templates ] localized impersonation targets used in campaigns – Apple, PayPay, Amazon, JCB Card, Rakuten Securities, and 10 more brands
- [Infrastructure / Services ] supporting services used for phishing operations – Alibaba domain registration service, VPS hosting, server rentals
- [Country / Region Targeting ] geographic targeting discussed in the article – Japan, the Americas, Europe, Australia, and the Middle East
- [Organization / Research Source ] intelligence and enforcement context – Google Threat Intelligence Group (GTIG), Google
Read more: https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/