Lighthouse is a China-based phishing-as-a-service operation associated with large-scale global smishing campaigns and payment-card theft. The service provides easy-to-use phishing kits, templated fraudulent websites, and supporting infrastructure that enable low-skill criminals to impersonate trusted brands and public-facing services at scale. Reported lures have prominently included postal and toll-payment themes, especially impersonation of USPS and E-ZPass, as well as Google-branded credential-harvesting pages. The operation has been described as affecting more than one million victims across more than 120 countries. Lighthouse functions as a criminal service ecosystem rather than a single isolated campaign. It has been marketed through Telegram-based channels and sold on subscription terms, with operators and customers coordinating phishing activity through social platforms. The kits support credential theft, payment-card theft, and interception of multi-factor authentication data, including one-time codes. Reporting also indicates use of fake MFA pages and real-time collection workflows to facilitate fraud and downstream monetization, including loading stolen card data into digital wallets. The actor is widely assessed as financially motivated. Its activity is centered on scalable fraud against consumers, with disproportionate targeting of U.S. victims through brand impersonation and SMS phishing. Lighthouse has also been linked in reporting to the broader Chinese-speaking phishing-kit ecosystem and has been associated by some reporting with the earlier name Smishing Triad. Google has pursued civil action against the operation under U.S. racketeering, trademark, and computer fraud statutes in an effort to disrupt its infrastructure and coordination channels.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another Chinese-speaking phishing kit/platform used for comparison with JWR, sharing behavioral similarities such as live operator puppeteering and OTP interception but not code-level overlap.
Named only as a comparison point among Chinese-speaking phishing kits; not part of the observed campaign.
Named phishing platform previously sued by Google and linked to large-scale victimization across 120 countries.
Massive China-based phishing-as-a-service platform whose operators were sued by Google after the service ensnared over 1 million users across 120 countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.