Wang Duo Yu is a Chinese threat actor linked by Cisco Talos with moderate confidence to the development and sale of smishing kits used by multiple financially motivated actors. Talos and other reporting tie Wang Duo Yu to toll-road and broader SMS phishing operations, including kits associated with Lighthouse and activity overlapping with the Smishing Triad ecosystem. Known aliases mentioned in the content include Lao Wang; PRODAFT tracks Wang Duo Yu (aka Lao Wang) as LARVA-241. According to the content, Wang Duo Yu develops and sells smishing kit source code, setup assistance, tutorials, and support via Telegram channels and a YouTube channel. Talos reported that Wang Duo Yu operated the Telegram channel "Lao Wang Synchronized Source Code Development Tutorial" from two Telegram accounts, where phishing modules spoofing toll systems such as Massachusetts MassDOT EZDriveMA and the North Texas Toll Authority were advertised. The actor also published YouTube tutorials covering mail server setup, payment systems, web panels, and proxy or node configuration, and offered one-on-one remote instruction. The kits attributed to Wang Duo Yu were used in a widespread toll-road smishing campaign targeting users across multiple U.S. states since October 2024. The campaign impersonated toll payment services such as E-ZPass, sent SMS or iMessage lures claiming small unpaid toll balances, and directed victims to typosquatted domains. Victims were taken through a fake CAPTCHA page, spoofed toll billing pages, and payment forms designed to steal personal information and payment card data. Talos assessed with moderate confidence that multiple threat actors were operating these campaigns using Wang Duo Yu’s kit. The content also states that Cisco Talos previously linked Lighthouse to smishing kits developed by Wang Duo Yu, and that Wang Duo Yu operated Telegram channels to sell and support Lighthouse phishing kits. Netcraft reported Lighthouse was marketed commercially with subscription pricing and customizable templates capable of stealing credentials and 2FA codes. Reporting cited in the content further notes overlaps between Lighthouse and other Chinese-linked smishing kits such as Darcula, Lucid, and Xiū gǒu, but only direct links to Wang Duo Yu described in the content are included here. Observed tradecraft directly mentioned in the content includes phishing kit development, phishing-as-a-service style sales and support, Telegram-based distribution and customer support, use of typosquatted domains, fake CAPTCHA gates, spoofed toll-payment portals, collection of personal and payment-card data, and infrastructure/setup guidance for operators. The content describes Wang Duo Yu as financially motivated and Chinese, but does not provide high-confidence evidence that this actor is a state-sponsored or nation-state threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese threat actor associated with developing and commercializing the Lighthouse phishing-as-a-service smishing kits (marketed via Telegram), enabling large-scale toll and delivery-themed SMS phishing campaigns that steal payment card data, credentials, and potentially 2FA codes via customizable phishing templates and typosquatted domains.
Developer and seller of smishing kits used in large-scale SMS phishing (smishing) campaigns targeting toll road users in the US and financial organizations in Australia and Asia-Pacific. The kits are sold to other threat actors and are backdoored to exfiltrate stolen data to the creator.
Developer and seller of smishing kits used in ongoing toll road payment phishing campaigns. Operates Telegram channels and related infrastructure to market source code, tutorials, VPS/cloud services, and setup assistance for phishing operations targeting toll operators, banks, and postal services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.