Lighthouse enterprise is an alleged China-based criminal phishing operation associated with large-scale SMS phishing and payment-card theft targeting U.S. consumers. The group is described as operating a phishing-kit ecosystem, selling easy-to-use kits and coordinating a broad member community through messaging platforms and other online services. Reported activity indicates the operation enabled thousands of participants to conduct impersonation-based scams at scale, including lures masquerading as trusted U.S. public-service and toll-related brands. The group’s core tradecraft centers on initial access through smishing, credential and payment-card data harvesting via phishing infrastructure, and subsequent monetization of stolen financial information. Reported post-compromise behavior includes loading stolen card data into mobile wallet services for fraudulent use. Operationally, the group has also used online channels to coordinate members and maintain infrastructure supporting phishing campaigns. Based on available reporting, Lighthouse enterprise is best characterized as a financially motivated cybercriminal service provider and scam network rather than a state-directed espionage actor. High-confidence reporting ties it to China as an operating base and to campaigns primarily harming victims in the United States. No additional well-established aliases or sub-groups are currently available from the supplied information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.