Lighthouse
Lighthouse is a phishing-as-a-service (PhaaS) / smishing kit associated with the Chinese-speaking, financially motivated Smishing Triad. Google and multiple cited reports describe it as tooling sold to enable low-skill operators to run large-scale SMS phishing and e-commerce fraud campaigns. The kit is used to send scam text messages and deliver links to fraudulent websites impersonating brands and agencies including USPS, E-ZPass, banks, Google properties, and other trusted services. Victims are lured with themes such as unpaid tolls, package redelivery fees, vehicle registration issues, and similar payment pretexts, then prompted to submit credentials, banking information, payment card data, and in some cases MFA codes.
Reported Lighthouse capabilities include phishing templates, domain setup tools, malicious SMS distribution support, and licensing models ranging from weekly to permanent subscriptions. Google reporting states the kits offer separate versions for SMS scams and e-commerce scams, include hundreds of fake-site templates, and have been used to generate very large numbers of phishing sites. The operation has been described as affecting more than 1 million victims across more than 120 countries, with reporting alleging theft of large volumes of U.S. payment card data. Researchers also reported more than 100 counterfeit templates impersonating Google login, Gmail, YouTube, and Google Play.
Recent reporting describes an evolution from previously documented PHP-based infrastructure to a Javalin/Kotlin-based phishing kit hosted on Alibaba Cloud. Observed infrastructure included a primary phishing server at 47.245.93.160 running Javalin on Jetty behind nginx, using Host-header-based routing for campaign-specific phishing pages, zero-byte 404 responses for unmatched hosts, a WebSocket-based admin panel at /console/, wildcard DNS, and rapid Let’s Encrypt certificate issuance. Campaign domains were observed to be rapidly rotated, often remaining active only 2 to 7 days, with 61 domains tracked over a 28-day period and registrations tied to Gname.com. Server-side exfiltration to the Telegram Bot API was reported, and oak-tel.com / Carrie SMS was identified as an SMS distribution platform used in the ecosystem.
A notable finding attributed the Lighthouse kit and core Smishing Triad tooling to Wang Duo Yu. Breakglass Intelligence reported that an obfuscated backdoor was embedded in the JQ.js file distributed with kit deployments. The backdoor allegedly stole operators’ Telegram bot tokens and exfiltrated them to a server controlled by Wang Duo Yu, giving him access to stolen victim data from downstream operators using the kit. Reported related infrastructure included 102.165.14.4 (telegrambotcheck.duckdns.org), described as a Windows-hosted Python Twisted web application handling token submission and validation via /receive_token on port 5000, with additional exposed services including RDP, WinRM, and RPC.
High-confidence infrastructure and behavioral indicators mentioned in the reporting include 47.245.93.160, 102.165.14.4, telegrambotcheck.duckdns.org, the Javalin servlet fingerprint io.javalin.jetty.JavalinJettyServlet-3ba0ae41, Telegram Bot API exfiltration via api.telegram.org/bot{TOKEN}/sendMessage, and the /console/ admin path. Lighthouse has been the subject of Google legal action in the U.S. District Court for the Southern District of New York, including RICO-related claims aimed at dismantling the operation’s infrastructure.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Wang Duo Yu, the developer behind the "Lighthouse" phishing kit and the Smishing Triad's core tooling, embeds an obfuscated backdoor in the JQ.js file distributed with every kit deployment.
Techniques & procedures
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
4 techniques
Resource Development
MITRE ATT&CK Mapping Technique ID Technique Application T1583.001 Acquire Infrastructure: Domains Automated bulk registration of 61+ domains via Gname.com API
MITRE ATT&CK Mapping Technique ID Technique Application T1583.003 Acquire Infrastructure: Virtual Private Server Alibaba Cloud Singapore VPS, IPXO-leased Windows server
Initial Access
2 techniques
Initial Access
Stealth
1 technique
Stealth
IOCs tracked for this family
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
Recent activity
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service kit used by the Smishing Triad to impersonate government and toll/vehicle services via smishing campaigns. The report describes a newer Javalin/Kotlin-based version with server-side Telegram exfiltration and an embedded backdoor that steals operators' Telegram bot tokens, giving the author access to stolen victim data across deployments.
Large-scale SMS phishing PhaaS platform used to target users across many countries by impersonating trusted brands.
A branded phishing-kit platform sold with subscription licenses that provides templates for fake websites, domain setup tools, and other features to enable large-scale SMS and e-commerce phishing campaigns aimed at stealing credentials and payment/banking data.
Phishing-as-a-service kit used to send text messages that phish victims for payment card data, reportedly hitting over one million victims across 120 countries.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.