YY Lai Yu is a Chinese-language phishing-as-a-service (PhaaS) platform associated with China-based cybercriminal activity. Since at least November 2025, it has operated as a mature criminal service offering hundreds of phishing templates and administrative tooling to enable large-scale credential and payment-data theft. The service is notable for strong localization, particularly against Japanese residents, expanding beyond generic banking lures to impersonate major Japanese consumer, financial, e-commerce, transport, and gaming brands and to exploit local themes such as loyalty-point redemption and seasonal electricity subsidy messaging. The platform supports bulk phishing operations through encrypted mobile messaging channels including RCS and iMessage, and it facilitates synchronized victim interaction to capture payment card details and one-time passwords in real time. Its phishing infrastructure uses anti-bot human-verification interstitials to hinder automated analysis. Administrative features include querying stolen data, filtering or prioritizing payment cards by BIN, geographic blocklisting, operator account and permission management, and integrated domain registration and management. These characteristics indicate a service-oriented criminal ecosystem designed to lower the barrier to entry for operators with limited technical skill while supporting scalable payment fraud and MFA bypass workflows. YY Lai Yu fits within a broader China-based criminal phishing ecosystem focused on payment card fraud, digital wallet tokenization abuse, and interception of authentication factors. Its observed activity is financially motivated and centered on phishing-enabled theft rather than espionage or disruptive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.