Lighthouse is a phishing-as-a-service (PhaaS) / smishing kit associated with the Chinese-speaking, financially motivated Smishing Triad. Google and other reporting describe it as a service that enables low-skill operators to run large-scale SMS phishing and e-commerce fraud campaigns using subscription-based access, domain setup tooling, and hundreds of branded phishing templates. It has been used in scam texts and related phishing infrastructure impersonating USPS, E-ZPass and other toll services, banks, healthcare organizations, payment platforms, law enforcement, social media services, and Google properties including Google login, Gmail, YouTube, and Google Play.
Its primary function is to send high-volume smishing messages containing links to spoofed websites that harvest credentials, payment card data, banking information, and other sensitive information. Reported lure themes include unpaid toll notices, package redelivery or stuck-package messages, vehicle registration themes, and e-commerce scams. Google reporting states the operation affected more than 1 million victims across more than 120 countries. Multiple sources also state the platform rapidly rotates infrastructure and uses evasion features to reduce exposure to browser warnings and Safe Browsing detections, allowing campaigns to resume with minimal downtime.
Supporting reporting attributes core Lighthouse tooling to Wang Duo Yu. Breakglass Intelligence reported a newer Javalin/Kotlin-based kit hosted on Alibaba Cloud infrastructure, replacing previously documented PHP-based tooling. Observed infrastructure included a primary phishing server at 47.245.93.160 on Alibaba Cloud in Singapore, using nginx as a reverse proxy to a Javalin application on Jetty, Host-header-based routing for campaign selection, wildcard DNS, and automated Let's Encrypt certificate issuance. The same reporting described a WebSocket-based admin panel at /console/ and server-side exfiltration to the Telegram Bot API via api.telegram.org/bot{TOKEN}/sendMessage.
A notable reported feature is an obfuscated backdoor embedded in JQ.js distributed with kit deployments. According to Breakglass Intelligence, this backdoor exfiltrates operators' Telegram bot tokens to 102.165.14.4 (telegrambotcheck.duckdns.org) via HTTP POST to /receive_token on port 5000 with parameter referrer=loco, allowing the developer to access stolen victim data from downstream operators using the kit. The token collection server was reported as a Windows host running Python Twisted (TwistedWeb/24.3.0), with exposed services including RDP on 3389, WinRM on 5985 and 47001, and RPC on 135. A related host at 102.165.14.2 was also identified.
Observed operational characteristics include bulk domain registration through Gname.com, short-lived campaign domains typically active for 2 to 7 days, and SMS distribution via oak-tel.com, also branded Carrie SMS. Reporting also links Lighthouse to very large-scale brand impersonation activity, including tens of thousands of USPS-themed phishing sites and extensive payment-card theft. High-confidence indicators directly mentioned in the content include 47.245.93.160, 102.165.14.4, 102.165.14.2, telegrambotcheck.duckdns.org, oak-tel.com, and the Javalin servlet fingerprint io.javalin.jetty.JavalinJettyServlet-3ba0ae41.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Wang Duo Yu, the developer behind the "Lighthouse" phishing kit and the Smishing Triad's core tooling, embeds an obfuscated backdoor in the JQ.js file distributed with every kit deployment.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping Technique ID Technique Application T1583.001 Acquire Infrastructure: Domains Automated bulk registration of 61+ domains via Gname.com API
MITRE ATT&CK Mapping Technique ID Technique Application T1583.003 Acquire Infrastructure: Virtual Private Server Alibaba Cloud Singapore VPS, IPXO-leased Windows server
MITRE ATT&CK Mapping Technique ID Technique Application T1199 Trusted Relationship Kit author backdoor exploits trust relationship with kit operators
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing kit cited as an example of brand-impersonation phishing-as-a-service used to create large numbers of fake domains.
A phishing-as-a-service kit used by the Smishing Triad to impersonate government and toll/vehicle services via smishing campaigns. The report describes a newer Javalin/Kotlin-based version with server-side Telegram exfiltration and an embedded backdoor that steals operators' Telegram bot tokens, giving the author access to stolen victim data across deployments.
Large-scale SMS phishing PhaaS platform used to target users across many countries by impersonating trusted brands.
A branded phishing-kit platform sold with subscription licenses that provides templates for fake websites, domain setup tools, and other features to enable large-scale SMS and e-commerce phishing campaigns aimed at stealing credentials and payment/banking data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.