Cybercriminals Offer Access to 'Lucid' Phishing Platform to Target iPhone, Android Phones in 88 Countries

Users who click on links are taken to ready-to-use phishing websites that collect personal information and credit card details.

Advertisement
Written by David Delima | Updated: 3 April 2025 13:52 IST
Highlights
  • Chinese cybercriminals are offering access to Lucid, a phishing platform
  • The service allows anyone to operate a phishing campaign
  • Fake phishing messages sent via Lucid ask for toll and parking charges

Lucid offers phishing websites with validation tools for collected credit card details

Cybercriminals are using massive device farms that comprise iPhone and Android smartphones in order to send phishing messages to users in 88 countries, according to security researchers. The 'Lucid' phishing-as-a-service (PhaaS) platform is designed to deliver messages via iMessage and rich communication services (RCS) chats, with links that lead to phishing websites. These messages are capable of evading typical SMS spam filters due to end-to-end encryption (E2EE). The cybercriminals are also selling licences to use the Lucid platform via a Telegram channel.

Lucid Platform Claimed to Deliver Over 100,000 Messages Every Day

Unlike regular SMS, messages are delivered to users via iMessage or RCS on iPhone and Android smartphones, respectively. As these are E2EE messaging services, the messages have a higher delivery rate than SMS phishing messages, according to Prodaft's report. These messages are also cheaper than SMS, as there are no operator charges.

Advertisement

One of the alleged device farms used to send tests via iMessage
Photo Credit: Prodaft

Advertisement

 

In order to deliver a high volume of messages via iMessage, Lucid uses large iOS device farms that use rotating, temporary Apple IDs. On the other hand, the cybercriminals use "carrier implementation inconsistencies in sender verification" to send RCS messages to unsuspecting users. 

Advertisement

The messages are designed to convince users to click on a phishing link, which leads to one of several phishing websites set up on over 1,000 domains owned by the threat actors. For example, some messages prompt users to complete fake toll payments, in order to avoid fines. On iMessage, recipients are even asked to respond, as links are disabled in new texts from unknown senders.

The ready-to-use phishing websites allow cybercriminals to collect people's details, including their credit card information. They can then use a validator to verify whether the card details are valid, before using or selling the information.

Advertisement

Lucid is operated as a PhaaS platform by a Chinese group known as XinXin, according to the researchers. Access to the platform is sold on a weekly basis via a Telegram channel. They are believed to be behind other platforms such as Darcula and Lighthouse, which also offer similar PhaaaS functionality.

In order to stay safe from these phishing attacks, users should refrain from clicking on links in messages received from unknown users. When in doubt about the authenticity of a message, users can contact the sender by looking up the official contact details online, or log in to a service that they use and check for pending payments.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Phishing, iMessage, RCS, iPhone, Android
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9s Pro Launched With 200-Megapixel Cameras: See Price, Features
  2. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  3. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  4. Vivo X300 FE Roundup: Expected Price in India, Specifications
  5. These Vivo Smartphones Will Cost More in India Due to the Latest Price Hike
  6. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC
  7. OnePlus Ace 6 Ultra's Key Specifications Surface via Geekbench Listing
  8. Oppo Pad 5 Pro With 13,380mAh Battery Debuts Alongside Pad Mini: See Prices
  9. Tim Cook to Step Down as Apple CEO as John Ternus Named Successor
  10. Apple's iOS 27 Update Might Drop Support for These iPhone Models
  1. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  2. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  3. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  4. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  5. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  6. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  7. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  8. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  9. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  10. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.