Target Industry
Indiscriminate, opportunistic targeting.
Overview
A new phishing-as-a-service (PhaaS) platform, Lucid, has emerged, exploiting vulnerabilities in Apple’s iMessage and Android’s Rich Communication Services (RCS). Operated by Chinese-speaking threat actors, Lucid boasts a success rate of around 5% – this is significantly higher than typical phishing campaigns.
Impact
Lucid is a widespread phishing campaign that has targeted 169 organisations across 88 countries, including the US and many in Europe. It uses a scalable, subscription-based model, allowing threat actors to harvest credit card details for financial fraud. There are claims of Lucid harvesting over 100,000 cards per day.
Exploitation
Lucid exploits vulnerabilities in Apple’s iMessage and Android’s RCS through several sophisticated techniques. It automates the process of sending phishing messages, making it easier to launch large-scale campaigns. The platform allows threat actors to create customisable phishing websites that mimic legitimate sites, tricking users into entering their sensitive information.
By using iMessage and RCS, Lucid can bypass traditional SMS spam filters, increasing the likelihood of the phishing messages reaching the target. Additionally, Lucid incorporates IP blocking and user-agent filtering to avoid detection by security systems. The platform includes a built-in card generator to validate and exploit stolen payment data, ensuring the harvested information is usable for financial fraud.
Containment, Mitigations & Remediations
Mitigating the risks posed by advanced phishing kits like Lucid requires a multi-layered approach. Here are some effective strategies:
- Enhance email security: use advanced email filtering and implement more robust multi-factor authentication (MFA) solutions
- Regular software updates: ensure all systems and software are up to date with the latest security patches, closing any vulnerabilities
- Employee training and awareness: set up phishing awareness training and use phishing simulations to help employees recognise and avoid phishing attempts
- Strong password policies: use strong, unique passwords and regular password changes, along with password managers
Threat Landscape
Lucid PhaaS has a broad reach due to targeting both Apple and Android devices. This enables threat actors to conduct large-scale phishing campaigns, affecting entities across many countries. Given its advanced infrastructure and persistent activity, Lucid poses a significant and ongoing cyber threat.
Threat Groups
Lucid PhaaS is operated by Chinese cybercriminals, who are also known as Black Technology or XinXin. Active since 2023, they have been responsible for deploying large-scale phishing campaigns that exploit mobile messaging protocols.
Further Information













