Lucid is a phishing-as-a-service operation associated with the broader Chinese-speaking smishing ecosystem. It has been referenced alongside other industrialized phishing platforms such as Lighthouse and Darcula in campaigns that impersonate trusted brands and public-service entities to steal payment information and personal data. Reporting has linked Lucid to large-scale SMS phishing activity and to infrastructure patterns shared with other Chinese-speaking phishing-kit operators, including use of similar fake storefront templates. High-confidence technical detail on Lucid itself is limited in the available material. It is identified as a PhaaS platform similar to Lighthouse, but there is no direct code-level linkage established between Lucid and the JWR framework. The available evidence supports characterizing Lucid as part of a financially motivated phishing ecosystem that enables credential and payment-data theft through spoofed web experiences delivered via smishing campaigns. Specific sub-groups, operators, and victimology beyond this ecosystem-level association are not currently available at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another Chinese-speaking phishing kit/platform used for comparison with JWR, sharing behavioral similarities such as live operator puppeteering and OTP interception but not code-level overlap.
Named only as a comparison point among Chinese-speaking phishing kits; not part of the observed campaign.
PhaaS platform similar to Lighthouse, associated with phishing campaigns leveraging large numbers of phishing domains targeting many brands across multiple countries.
Named Chinese phishing-as-a-service operator/group; reported to share a distinctive phishing/fake-shop template ('LOAFING OUT LOUD') with Lighthouse, suggesting possible operational linkage or shared tooling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.