Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Phishing

Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit

Google is targeting the threat group known as Smishing Triad, which used over 194,000 malicious domains in a campaign. 

Phishing

Google on Tuesday announced that it has filed a lawsuit against a cybercrime group believed to be operating out of China.

The group, known as Smishing Triad, has been active since at least 2023, targeting users around the world in large-scale SMS phishing (smishing) campaigns. 

The group’s malicious SMS messages impersonate toll and package delivery services — Google provided E-ZPass and USPS as an example — as well as banks, healthcare organizations, online payment platforms, law enforcement, and social media services.

Google has targeted Lighthouse, a recently launched phishing-as-a-service kit that enables cybercriminals to send out messages containing links to phishing sites. The malicious sites are set up to trick users into handing over email credentials, banking details, and other sensitive information. 

According to Google, the Lighthouse kit enabled the targeting of more than one million users across over 120 countries, with an estimated 12 million to 115 million credit cards being stolen in the United States alone.

Palo Alto Networks reported recently that a Smishing Triad campaign involved more than 194,000 malicious domains.

Advertisement. Scroll to continue reading.

Google said it identified over 100 phishing website templates impersonating its brand and services.

“Our legal action is designed to dismantle the core infrastructure of this operation,” explained Halimah DeLaine Prado, general counsel at Google. “We are bringing claims under the Racketeer Influenced and Corrupt Organizations Act, the Lanham Act, and the Computer Fraud and Abuse Act to shut it down, protecting users and other brands.”

Filing lawsuits against cybercriminals — even without knowing their identity — enables major tech companies to obtain court orders for seizing malicious domains. In addition, lawsuits allow the companies to subpoena ISPs, registrars, and hosting providers to obtain IPs and other technical information associated with the operation and the defendants, which can ultimately lead to unmasking their true identities. 

Microsoft has also filed lawsuits in an effort to disrupt cybercrime operations. Recent examples include the ONNX and RaccoonO365 phishing services.

In addition to its lawsuit, Google says its fight against scammers includes endorsing several bipartisan bills aimed at cyber-enabled threats.

This includes the Guarding Unprotected Aging Retirees from Deception (GUARD) Act, which would empower law enforcement to investigate fraud and scams aimed at retirees; the Foreign Robocall Elimination Act, calling for the creation of a taskforce focused on blocking foreign robocalls; and the Scam Compound Accountability and Mobilization (SCAM) Act, which would develop a national strategy to counter scam compounds.

Related: Lumma Stealer Malware Returns After Takedown Attempt

Related: Archetyp Dark Web Market Shut Down by Law Enforcement

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

1Kosmos has named Frank Cohen Chief Revenue Officer.

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.