Wang Duo Yu is a Chinese cybercriminal figure associated with the development, sale, and support of commercial smishing and phishing kits used in large-scale financial theft campaigns. Reporting links the actor to toll-road and postal-service impersonation operations and to the Lighthouse phishing-as-a-service ecosystem, with additional overlap noted with activity commonly discussed alongside the Smishing Triad. Wang Duo Yu has also been referred to as Lao Wang. The actor is associated with creating phishing kits that enable other threat actors to conduct SMS phishing campaigns at scale. These kits have been used to impersonate U.S. toll payment services such as E-ZPass and related regional toll authorities, luring victims with claims of unpaid balances and late fees. The phishing flow commonly uses spoofed payment portals, fake CAPTCHA stages, and branded billing pages to harvest personally identifiable information and payment card data. Broader reporting also indicates support for templates used in postal-delivery and financial-themed smishing, including credential and two-factor authentication theft in some variants. Wang Duo Yu is linked to the commercial distribution of these kits through Telegram channels and tutorial content, including infrastructure setup guidance, phishing panel configuration, proxy or node configuration, and one-on-one support. This positions the actor less as a single intrusion operator and more as an enabler within a wider cybercrime ecosystem, supplying tooling and operational assistance to multiple financially motivated actors. The associated ecosystem has been described as global in reach, with campaigns affecting victims across many countries, while the toll-road activity specifically has targeted users in multiple U.S. states. High-confidence reporting supports financial motivation and capabilities centered on initial access through smishing, credential and payment-data theft, and exfiltration of victim-submitted information. Some reporting also notes that kits associated with this ecosystem can facilitate session-related theft through collection of authentication factors, and that the broader operator community uses brand spoofing and other defense-evasion measures to improve delivery and conversion. Attribution to China is supported for the actor and the surrounding service ecosystem, but some details about precise organizational relationships among Wang Duo Yu, Lighthouse, and the Smishing Triad remain assessed rather than definitively established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese threat actor associated with developing and commercializing the Lighthouse phishing-as-a-service smishing kits (marketed via Telegram), enabling large-scale toll and delivery-themed SMS phishing campaigns that steal payment card data, credentials, and potentially 2FA codes via customizable phishing templates and typosquatted domains.
Developer and seller of smishing kits used in large-scale SMS phishing (smishing) campaigns targeting toll road users in the US and financial organizations in Australia and Asia-Pacific. The kits are sold to other threat actors and are backdoored to exfiltrate stolen data to the creator.
Developer and seller of smishing kits used in ongoing toll road payment phishing campaigns. Operates Telegram channels and related infrastructure to market source code, tutorials, VPS/cloud services, and setup assistance for phishing operations targeting toll operators, banks, and postal services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.