Target Industry

Indiscriminate, opportunistic targeting. 

Overview

A new phishing-as-a-service (PhaaS) platform, Lucid, has emerged, exploiting vulnerabilities in Apple’s iMessage and Android’s Rich Communication Services (RCS). Operated by Chinese-speaking threat actors, Lucid boasts a success rate of around 5% – this is significantly higher than typical phishing campaigns. 

Impact

Lucid is a widespread phishing campaign that has targeted 169 organisations across 88 countries, including the US and many in Europe. It uses a scalable, subscription-based model, allowing threat actors to harvest credit card details for financial fraud. There are claims of Lucid harvesting over 100,000 cards per day. 

Exploitation

Lucid exploits vulnerabilities in Apple’s iMessage and Android’s RCS through several sophisticated techniques. It automates the process of sending phishing messages, making it easier to launch large-scale campaigns. The platform allows threat actors to create customisable phishing websites that mimic legitimate sites, tricking users into entering their sensitive information. 

By using iMessage and RCS, Lucid can bypass traditional SMS spam filters, increasing the likelihood of the phishing messages reaching the target. Additionally, Lucid incorporates IP blocking and user-agent filtering to avoid detection by security systems. The platform includes a built-in card generator to validate and exploit stolen payment data, ensuring the harvested information is usable for financial fraud. 

Containment, Mitigations & Remediations

Mitigating the risks posed by advanced phishing kits like Lucid requires a multi-layered approach. Here are some effective strategies: 

  • Enhance email security: use advanced email filtering and implement more robust multi-factor authentication (MFA) solutions 
  • Regular software updates: ensure all systems and software are up to date with the latest security patches, closing any vulnerabilities 
  • Employee training and awareness: set up phishing awareness training and use phishing simulations to help employees recognise and avoid phishing attempts 
  • Strong password policies: use strong, unique passwords and regular password changes, along with password managers 

Threat Landscape

Lucid PhaaS has a broad reach due to targeting both Apple and Android devices. This enables threat actors to conduct large-scale phishing campaigns, affecting entities across many countries. Given its advanced infrastructure and persistent activity, Lucid poses a significant and ongoing cyber threat. 

Threat Groups

Lucid PhaaS is operated by Chinese cybercriminals, who are also known as Black Technology or XinXin. Active since 2023, they have been responsible for deploying large-scale phishing campaigns that exploit mobile messaging protocols. 

Further Information

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content