Lucid is a phishing-as-a-service operation associated with the broader Chinese-speaking smishing ecosystem. It has been referenced alongside other industrialized phishing platforms such as Lighthouse and Darcula in campaigns that impersonate trusted brands and public-service entities to steal payment information and personal data. Reporting has linked Lucid to large-scale SMS phishing activity and to infrastructure patterns shared with other Chinese-speaking phishing-kit operators, including use of similar fake storefront templates. High-confidence technical detail on Lucid itself is limited in the available material. It is identified as a PhaaS platform similar to Lighthouse, but there is no direct code-level linkage established between Lucid and the JWR framework. The available evidence supports characterizing Lucid as part of a financially motivated phishing ecosystem that enables credential and payment-data theft through spoofed web experiences delivered via smishing campaigns. Specific sub-groups, operators, and victimology beyond this ecosystem-level association are not currently available at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another Chinese-speaking phishing kit/platform used for comparison with JWR, sharing behavioral similarities such as live operator puppeteering and OTP interception but not code-level overlap.
Named only as a comparison point among Chinese-speaking phishing kits; not part of the observed campaign.
PhaaS platform similar to Lighthouse, associated with phishing campaigns leveraging large numbers of phishing domains targeting many brands across multiple countries.
Named Chinese phishing-as-a-service operator/group; reported to share a distinctive phishing/fake-shop template ('LOAFING OUT LOUD') with Lighthouse, suggesting possible operational linkage or shared tooling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.