Skip to main content
Mallory
MalwareUsed by 1 actor

Lighthouse

Lighthouse is a phishing-as-a-service (PhaaS) / smishing kit associated with the Chinese-speaking, financially motivated Smishing Triad. Google and multiple cited reports describe it as tooling sold to enable low-skill operators to run large-scale SMS phishing and e-commerce fraud campaigns. The kit is used to send scam text messages and deliver links to fraudulent websites impersonating brands and agencies including USPS, E-ZPass, banks, Google properties, and other trusted services. Victims are lured with themes such as unpaid tolls, package redelivery fees, vehicle registration issues, and similar payment pretexts, then prompted to submit credentials, banking information, payment card data, and in some cases MFA codes.

Reported Lighthouse capabilities include phishing templates, domain setup tools, malicious SMS distribution support, and licensing models ranging from weekly to permanent subscriptions. Google reporting states the kits offer separate versions for SMS scams and e-commerce scams, include hundreds of fake-site templates, and have been used to generate very large numbers of phishing sites. The operation has been described as affecting more than 1 million victims across more than 120 countries, with reporting alleging theft of large volumes of U.S. payment card data. Researchers also reported more than 100 counterfeit templates impersonating Google login, Gmail, YouTube, and Google Play.

Recent reporting describes an evolution from previously documented PHP-based infrastructure to a Javalin/Kotlin-based phishing kit hosted on Alibaba Cloud. Observed infrastructure included a primary phishing server at 47.245.93.160 running Javalin on Jetty behind nginx, using Host-header-based routing for campaign-specific phishing pages, zero-byte 404 responses for unmatched hosts, a WebSocket-based admin panel at /console/, wildcard DNS, and rapid Let’s Encrypt certificate issuance. Campaign domains were observed to be rapidly rotated, often remaining active only 2 to 7 days, with 61 domains tracked over a 28-day period and registrations tied to Gname.com. Server-side exfiltration to the Telegram Bot API was reported, and oak-tel.com / Carrie SMS was identified as an SMS distribution platform used in the ecosystem.

A notable finding attributed the Lighthouse kit and core Smishing Triad tooling to Wang Duo Yu. Breakglass Intelligence reported that an obfuscated backdoor was embedded in the JQ.js file distributed with kit deployments. The backdoor allegedly stole operators’ Telegram bot tokens and exfiltrated them to a server controlled by Wang Duo Yu, giving him access to stolen victim data from downstream operators using the kit. Reported related infrastructure included 102.165.14.4 (telegrambotcheck.duckdns.org), described as a Windows-hosted Python Twisted web application handling token submission and validation via /receive_token on port 5000, with additional exposed services including RDP, WinRM, and RPC.

High-confidence infrastructure and behavioral indicators mentioned in the reporting include 47.245.93.160, 102.165.14.4, telegrambotcheck.duckdns.org, the Javalin servlet fingerprint io.javalin.jetty.JavalinJettyServlet-3ba0ae41, Telegram Bot API exfiltration via api.telegram.org/bot{TOKEN}/sendMessage, and the /console/ admin path. Lighthouse has been the subject of Google legal action in the U.S. District Court for the Southern District of New York, including RICO-related claims aimed at dismantling the operation’s infrastructure.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Smishing Triad

Wang Duo Yu, the developer behind the "Lighthouse" phishing kit and the Smishing Triad's core tooling, embeds an obfuscated backdoor in the JQ.js file distributed with every kit deployment.

via breakglass intelintel.breakglass.tech
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

4 techniques
T1583.001DomainsEvidence1

MITRE ATT&CK Mapping Technique ID Technique Application T1583.001 Acquire Infrastructure: Domains Automated bulk registration of 61+ domains via Gname.com API

T1583.003Virtual Private ServerEvidence1

MITRE ATT&CK Mapping Technique ID Technique Application T1583.003 Acquire Infrastructure: Virtual Private Server Alibaba Cloud Singapore VPS, IPXO-leased Windows server

T1585.002Email AccountsEvidence1

MITRE ATT&CK Mapping Technique ID Technique Application T1585.002 Establish Accounts: Email Accounts Singapore-based registrar accounts for domain procurement

T1608.005Link TargetEvidence1

MITRE ATT&CK Mapping Technique ID Technique Application T1608.005 Stage Capabilities: Link Target State-targeted phishing pages with multi-stage data collection

Initial Access

2 techniques
T1199Trusted RelationshipEvidence1

MITRE ATT&CK Mapping Technique ID Technique Application T1199 Trusted Relationship Kit author backdoor exploits trust relationship with kit operators

T1566.001Spearphishing AttachmentEvidence1

MITRE ATT&CK Mapping Technique ID Technique Application T1566.001 Phishing: Spearphishing Link SMS messages with malicious URLs to state-impersonating domains

Stealth

1 technique
T1036.005Match Legitimate Resource Name or LocationEvidence1

MITRE ATT&CK Mapping Technique ID Technique Application T1036.005 Masquerading: Match Legitimate Name or Location gov-*.bond domains with US state abbreviation subdomains

Exfiltration

1 technique
T1567.003Exfiltration to Text Storage SitesEvidence1

MITRE ATT&CK Mapping Technique ID Technique Application T1567.003 Exfiltration Over Web Service: Exfiltration to Cloud Storage Telegram Bot API used for real-time exfiltration of stolen data

INDICATORS OF COMPROMISE

IOCs tracked for this family

21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
20 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
uri●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
ACTIVITY FEED

Recent activity

12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching21

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.