Smishing Triad is a Chinese-speaking, financially motivated cybercrime ecosystem focused on large-scale SMS and mobile-message phishing, commonly operated as phishing-as-a-service. Active since at least 2023, it is widely associated with mass smishing campaigns that impersonate postal services, toll road operators, government agencies, banks, e-commerce platforms, payment providers, logistics companies, and other trusted brands in order to steal credentials, payment card data, personal information, and other sensitive financial data. The activity has affected victims globally across more than 120 countries. The group is best known for industrialized smishing operations using fraudulent delivery, unpaid toll, customs, vehicle registration, tax, and account-alert themes. Campaigns are tailored by geography and brand, with especially heavy impersonation of postal services and tolling providers, but reporting also links the ecosystem to campaigns targeting financial services, brokerage accounts, cryptocurrency platforms, healthcare, law enforcement, social media, and government services. Researchers have also observed regional targeting in the Middle East, Southeast Asia, Japan, and Egypt. Smishing Triad is commonly linked to a broader Chinese-origin phishing-kit ecosystem that includes Lighthouse, Darcula, Lucid, and related offerings; Google has referred to the operators behind Lighthouse as the “Lighthouse Enterprise.” Lighthouse emerged as a prominent rebrand in early 2025 and has been described as a subscription-based or franchised phishing kit rented to other criminals, enabling low-skill affiliates to launch polished phishing campaigns at scale. The ecosystem appears decentralized, with specialized roles spanning kit development, domain provisioning, hosting, spam delivery, victim-data monetization, liveness checking, and blocklist evasion. Tradecraft associated with Smishing Triad includes rapid bulk domain registration, short-lived infrastructure, brand impersonation at massive scale, mobile-optimized phishing pages, geofencing, browser and header-based filtering, selective content delivery, wildcard DNS, automated TLS issuance, and rapid infrastructure rotation to evade takedowns and reputation systems. Campaigns have used both traditional SMS and internet-based mobile messaging channels such as Apple iMessage and Android RCS, helping bypass some carrier-based spam filtering. Researchers have also observed use of Chinese-language support and sales channels on Telegram and video platforms to market kits, training, and operational support. The ecosystem has been tied to very large domain volumes and high operational churn, with hundreds of thousands of phishing domains and templates observed across campaigns. Public reporting and litigation allege that the operation has victimized more than one million people worldwide and enabled theft at very large scale, including extensive payment-card compromise. Some reporting also links the ecosystem’s stolen data to downstream fraud such as carding, merchant fraud, account takeover, and brokerage-account abuse. Known aliases and related labels include Smishing-Triad and Lighthouse Enterprise. Closely associated platforms and sub-ecosystem names include Lighthouse, Darcula, Lucid, and Panda Shop. Attribution consistently points to a China-linked criminal ecosystem rather than a state-sponsored espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
84 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a franchised smishing platform that rents out ready-made phishing kits for toll, postal, banking, and brand impersonation scams, enabling large-scale SMS/iMessage/RCS fraud campaigns worldwide.
A phishing-as-a-service smishing ecosystem targeting UAE and Singapore government, transportation, and logistics services for financial fraud, credential harvesting, payment card theft, and possible compromise of digital identity platforms such as UAE Pass.
Large-scale phishing-as-a-service and SMS smishing operation using the Lighthouse phishing kit, state-impersonating domains, Telegram-based exfiltration, and evolving infrastructure including a Javalin/Kotlin-based phishing kit.
Conducts large-scale smishing/phishing campaigns (e.g., E‑ZPass-themed lures) using impersonation tactics to steal funds/credentials and facilitate cryptocurrency-related fraud.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.