By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading:  Google Sues China-Based Hackers Behind $1 Billion Lighthouse Phishing Platform
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing >  Google Sues China-Based Hackers Behind $1 Billion Lighthouse Phishing Platform
Computing

 Google Sues China-Based Hackers Behind $1 Billion Lighthouse Phishing Platform

News Room
Last updated: 2025/11/12 at 12:38 PM
News Room Published 12 November 2025
Share
 Google Sues China-Based Hackers Behind  Billion Lighthouse Phishing Platform
SHARE

Nov 12, 2025Ravie LakshmananCybercrime / Malware

Google has filed a civil lawsuit in the U.S. District Court for the Southern District of New York (SDNY) against China-based hackers who are behind a massive Phishing-as-a-Service (PhaaS) platform called Lighthouse that has ensnared over 1 million users across 120 countries.

The PhaaS kit is used to conduct large-scale SMS phishing attacks that exploit trusted brands like E-ZPass and USPS to steal people’s financial information by prompting them to click on a link using lures related to fake toll fees or package deliveries. While the scam in itself is fairly simple, it’s the industrial scale of the operation that has allowed it to illegally make more than a billion dollars over the past three years.

“They exploit the reputations of Google and other brands by illegally displaying our trademarks and services on fraudulent websites,” Halimah DeLaine Prado, General Counsel at Google, said. “We found at least 107 website templates featuring Google’s branding on sign-in screens specifically designed to trick people into believing the sites are legitimate.”

DFIR Retainer Services

The company said it’s taking legal action to dismantle the underlying infrastructure under the Racketeer Influenced and Corrupt Organizations (RICO) Act, the Lanham Act, and the Computer Fraud and Abuse Act.

Lighthouse, along with other PhaaS platforms like Darcula and Lucid, is part of an interconnected cybercrime ecosystem operating out of China that is known to send thousands of smishing messages via Apple iMessage and Google Messages’ RCS capabilities to users in the U.S. and beyond in hopes of stealing sensitive data. These kits have been put to use by a smishing syndicate tracked as Smishing Triad.

In a report published in September, Netcraft revealed that Lighthouse and Lucid have been linked to more than 17,500 phishing domains targeting 316 brands from 74 countries. Phishing templates associated with Lighthouse are licensed from anywhere between $88 for a week to $1,588 for a yearly subscription.

“While Lighthouse operates independently of the XinXin group, its alignment with Lucid in terms of infrastructure and targeting patterns highlights the broader trend of collaboration and innovation within the PhaaS ecosystem,” Swiss cybersecurity company PRODAFT said in a report published in April.

CIS Build Kits

It’s estimated that Chinese smishing syndicates may have compromised between 12.7 million and 115 million payment cards in the U.S. alone between July 2023 and October 2024. In recent years, cybercrime groups from China have also evolved to develop new tools like Ghost Tap to add stolen card details to digital wallets on iPhones and Android phones.

As recently as last month, Palo Alto Networks Unit 42 said the threat actors behind Smishing Triad have used more than 194,000 malicious domains since January 1, 2024, mimicking a wide range of services, including banks, cryptocurrency exchanges, mail and delivery services, police forces, state-owned enterprises, and electronic tolls, among others.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Cyber bill offers ‘no guarantee of security’, tech lawyer says – UKTN Cyber bill offers ‘no guarantee of security’, tech lawyer says – UKTN
Next Article Amazon’s New Fire TV Stick 4K Select drops 45% mere weeks after launch Amazon’s New Fire TV Stick 4K Select drops 45% mere weeks after launch
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

How the Steam Frame compares to other VR headsets
How the Steam Frame compares to other VR headsets
News
What are social media management tools and why use them?
What are social media management tools and why use them?
Computing
Anthropic, Microsoft announce new AI data center projects as industry's construction push continues
Anthropic, Microsoft announce new AI data center projects as industry's construction push continues
News
What Do Developers Ask ChatGPT the Most? | HackerNoon
What Do Developers Ask ChatGPT the Most? | HackerNoon
Computing

You Might also Like

What are social media management tools and why use them?
Computing

What are social media management tools and why use them?

34 Min Read
What Do Developers Ask ChatGPT the Most? | HackerNoon
Computing

What Do Developers Ask ChatGPT the Most? | HackerNoon

15 Min Read
Valve surprises with 3 new hardware devices in a full-circle moment for gaming giant
Computing

Valve surprises with 3 new hardware devices in a full-circle moment for gaming giant

4 Min Read
The State Of The Vulkan Renderer For Wayland’s Weston 15.0 Compositor
Computing

The State Of The Vulkan Renderer For Wayland’s Weston 15.0 Compositor

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?