Lucid is a phishing-as-a-service (PhaaS) platform referenced in reporting on large-scale smishing campaigns. The content describes Lucid as a platform very similar to Lighthouse and notes that similar campaigns have been attributed to other Chinese threat actors running PhaaS platforms, such as Darcula and Lucid. Netcraft is cited as discussing campaigns believed to be associated with Lighthouse and Lucid, and reported detecting more than 17,500 phishing domains targeting 316 brands across 74 countries after identifying these campaigns. The content also states that Lighthouse used the same "LOAFING OUT LOUD" fake shop template as Lucid, indicating a possible connection between the groups. Beyond this possible linkage and its role as a similar PhaaS/smishing platform, further high-confidence details on Lucid’s operators, sub-groups, or specific tactics are not directly provided in the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PhaaS platform similar to Lighthouse, associated with phishing campaigns leveraging large numbers of phishing domains targeting many brands across multiple countries.
Named Chinese phishing-as-a-service operator/group; reported to share a distinctive phishing/fake-shop template ('LOAFING OUT LOUD') with Lighthouse, suggesting possible operational linkage or shared tooling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.