Skip to content
Chinese-Language Phishing Services Adopt AI and Real-Time MFA Bypass, GTIG Says

Chinese-Language Phishing Services Adopt AI and Real-Time MFA Bypass, GTIG Says

Technadu May 26, 2026

Google Threat Intelligence Group (GTIG) recently analyzed a dozen active Chinese-language phishing-as-a-service (PhaaS) offerings, identifying a rapidly growing underground ecosystem. Departing from traditional static password harvesting, these sophisticated threat actors now prioritize real-time interception and tokenization techniques.

To distribute these threats, Chinese-language operators heavily leverage encrypted communication protocols, specifically RCS and Apple iMessage, according to GTIG. The primary tactical objective focuses on exploiting digital wallet provisioning.

“This shift represents an emerging development where the goal is no longer just a login, but securing direct, unauthorized control over a victim's financial accounts ,” the report says.

Furthermore, the ecosystem exhibits a widespread adoption of AI-based automation to enhance scalability and stealth. The Darcula platform, which Google links to the threat actor UNC5814, exemplifies this shift by utilizing AI -powered page generators and browser automation tools like Puppeteer to bypass conventional detection mechanisms.

The Chinese -language PhaaS ecosystem:

A prominent case study within this ecosystem is YY Lai Yu, a platform first advertised in August 2024. While the infrastructure supports phishing operations across 119 countries, its largest strategic focus remains on Japan . The service provides extensive localized targeting capabilities, offering more than 400 specific phishing templates to its affiliates since November 2025.

These sophisticated lures target users of major regional and international brands, including Amazon, Apple, DMM, Epos Card, JA Bank, JCB Card, JR, Matsui Securities, Mercari, Monex, Nintendo, Nomura Securities, Orico Card, PayPay, Rakuten Securities, and Sagawa Express.

GTIG says the proliferation of the Chinese-language PhaaS ecosystem underscores a need for technical security controls that go beyond user education and recommends:

The Talos 2025 Year in Review report last month said global cybersecurity risks are led by state- groups, with China-nexus threat activity increasing by 75% .

Security researchers linked 2025 phishing attempts targeting US E-ZPass toll payment systems via iMessage and SMS to the PhaaS services Darcula and Lucid. In March, an INTERPOL report said AI-enhanced scams are four times more profitable .

Extracted Entities

APT Groups (1)

Attack Types (1)

Countries (1)

Platforms (1)

Tools (1)