<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Phaas — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/phaas/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 25 May 2026 05:10:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/phaas/feed.xml" rel="self" type="application/rss+xml"/><item><title>Emergence of Chinese-Language Phishing-as-a-Service (PhaaS) Ecosystem</title><link>https://feed.craftedsignal.io/briefs/2026-05-chinese-phaas/</link><pubDate>Mon, 25 May 2026 05:10:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-05-chinese-phaas/</guid><description>A rapidly growing Chinese-language PhaaS ecosystem is shifting towards real-time interception of credentials and tokenization of stolen payment data, bypassing traditional SMS security filters with encrypted channels like RCS and iMessage, and employing AI-based automation to evade detection.</description><content:encoded><![CDATA[<p>A thriving Phishing-as-a-Service (PhaaS) ecosystem is emerging within the Chinese-language cybercrime landscape, challenging the dominance of Russian-speaking actors. This ecosystem features mature services intricately linked to the regional criminal underground, lowering the barrier to entry for Chinese cyber criminals. Instead of static password harvesting, these services leverage real-time interception and tokenization to bypass multifactor authentication (MFA). They exploit digital wallet provisioning to transform stolen payment data into tokenized assets, enabling direct, unauthorized control over victims&rsquo; financial accounts. This shift, combined with encrypted delivery channels, represents a significant evolution in social engineering and credential theft, moving beyond simple account access towards financial exploitation. The YY Lai Yu (YY来鱼) platform, advertised since August 2024, targets 119 countries, with a focus on Japan, exemplifying this trend.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attackers deliver phishing links via RCS and iMessage, leveraging their end-to-end encryption to bypass traditional SMS security filters.</li>
<li>The victim clicks the malicious link, leading them to a phishing page that mimics a legitimate service.</li>
<li>The victim enters their credentials and, if applicable, an OTP on the phishing page.</li>
<li>The attacker, using a real-time administration panel, intercepts the credentials and OTP instantly as the victim enters them.</li>
<li>The attacker uses the stolen credentials and OTP to provision the victim&rsquo;s payment card into a digital wallet on an attacker-controlled device.</li>
<li>The tokenized card is then used for high-value transactions, contactless payments, and ATM withdrawals.</li>
<li>Some PhaaS operators utilize AI-powered page generators, like those in the Darcula platform, to clone legitimate websites by replicating their HTML, CSS, JavaScript, and visual elements.</li>
<li>This AI-driven automation creates unique phishing pages, rendering signature-based detection methods less effective.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The shift towards real-time credential interception and tokenization of stolen payment data enables attackers to bypass MFA and gain unauthorized control over victims&rsquo; financial accounts. This can lead to significant financial losses through unauthorized transactions, contactless payments, and ATM withdrawals. The use of AI-powered phishing page generators increases the scale and stealth of these operations, making them more difficult to detect and defend against. While the source doesn&rsquo;t mention specific victim counts, the PhaaS targets the general public opportunistically.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor for the use of iMessage and RCS for potential phishing attempts, focusing on messages containing links to external websites to activate corresponding detections.</li>
<li>Implement detection mechanisms to identify AI-generated phishing pages by analyzing website characteristics and content similarity to known legitimate sites.</li>
<li>Deploy the Sigma rule detecting OTP interception based on access to admin panels to your SIEM and tune for your environment.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>phishing</category><category>phaas</category><category>credential-theft</category><category>social-engineering</category></item></channel></rss>