logo

2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services

ID: 39a7b7a2-ec14-57c8-8a13-ca5128eff46f

STIX ID: report--39a7b7a2-ec14-57c8-8a13-ca5128eff46f

Feed Name: Threat Intelligence

Threat Score
75/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: Google Threat Intelligence Group

...
...

GTIG observed a China-based phishing-as-a-service (PhaaS) operator, YY Lai Yu, offering 400+ highly localized Japanese phishing templates and comprehensive operator tooling that harvests payment card data and OTPs. The service leverages anti-bot human verification, encrypted bulk messaging (RCS/iMessage), domain registration automation, BIN-based filtering, and admin controls to scale and evade detection, and the report recommends stronger technical controls (e.g., FIDO2/WebAuthn, risk-based verification) to mitigate impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.