RCS and iMessage Phishing Bypasses SMS Security Filters
Key Takeaways Cybercriminals are increasingly using Rich Communication Services (RCS) and Apple iMessage for sophisticated phishing campaigns. These advanced messaging platforms bypass traditional...
Key Takeaways
- Cybercriminals are increasingly using Rich Communication Services (RCS) and Apple iMessage for sophisticated phishing campaigns.
- These advanced messaging platforms bypass traditional SMS security filters due to end-to-end encryption, making detection and blocking more challenging.
- Phishing-as-a-Service (PhaaS) platforms, particularly those in the Chinese-language underground, are enabling attackers to steal credentials and gain control over victims’ financial accounts, including digital wallet provisioning.
- The attacks aim for real-time financial control, enabling contactless payments, ATM withdrawals, and fund transfers without direct access to the victim’s physical device.
- Defenders should implement FIDO2/WebAuthn authentication and banks should enhance risk-based verification during digital wallet provisioning to mitigate these threats.
Sophisticated Phishing Campaigns Exploit RCS and iMessage to Bypass SMS Filters
Cybercriminals are significantly enhancing their phishing operations, leveraging advanced messaging protocols such as Rich Communication Services (RCS) and Apple’s iMessage to circumvent established SMS security measures. This strategic shift represents a critical escalation in how malicious actors target individuals, primarily to pilfer sensitive financial information.
Table Of Content
A comprehensive report reveals a growing trend in these sophisticated phishing endeavors. Rather than relying on standard SMS messages, which are often easily identified and blocked by carrier-level filters, threat actors are now employing encrypted communication channels like RCS and iMessage to deliver malicious links directly to victims’ mobile devices. This change in methodology marks a substantial advancement in the sophistication of contemporary phishing attacks.
Evolution of Phishing Objectives
The objectives of these cybercriminals have evolved beyond merely stealing usernames and passwords. Their current aim is to achieve complete, real-time control over victims’ financial accounts. This includes the capability to deplete funds, execute contactless payments, and perform ATM withdrawals, all without requiring physical access to the victim’s device. This level of access underscores a dangerous new frontier in financial fraud.
The Google Threat Intelligence Group (GTIG) recently shared a report detailing its analysis of a dozen active Phishing-as-a-Service (PhaaS) platforms operating within the Chinese-language underground. Researchers discovered these platforms to be mature, highly organized services that significantly lower the barrier to entry for aspiring cybercriminals, indicating a broader systemic change in how credential theft is executed at scale.
Historically, Russian-speaking actors have dominated the PhaaS landscape. However, a distinct and rapidly expanding Chinese-language ecosystem has emerged as a formidable competitor. These services are not simply imitations of their Russian counterparts; they function with their own unique organizational structures, target profiles, and internal culture, including threat actors who openly publicize their illicit earnings on platforms like Telegram.
Late last year, Google initiated legal proceedings against a PhaaS provider linked to this burgeoning ecosystem. Concurrently, the company has continued to advocate for legislative action and implement technical safeguards designed to counter these scams. Despite these ongoing efforts, the latest findings indicate that the ecosystem continues to expand and refine its deceptive methods.
Phishing Services Exploit Encrypted Messaging
Traditional SMS phishing, commonly known as smishing, faces increasing scrutiny from carrier-level filters designed to detect and block suspicious links. Chinese-language PhaaS operators have recognized this vulnerability and consequently migrated their delivery infrastructure to RCS and iMessage. A key advantage for attackers is that both protocols utilize end-to-end encryption, which significantly complicates network-level tools’ ability to inspect or block malicious content.
Beyond the technical evasion, these modern messaging platforms offer a more polished and credible user experience compared to basic text messages. They support features such as read receipts, typing indicators, high-resolution images, and group chats. When a phishing message arrives via these channels, its appearance is often convincingly legitimate, making it far more likely for an average user to interact with it. The combination of technical bypass and visual authenticity renders these campaigns exceptionally dangerous.
Once a victim clicks a malicious link and inputs their credentials, the stolen data instantly appears on the attacker’s live administration panel. The attacker then simultaneously triggers a One-Time Password (OTP) request on their own device just as the victim is prompted for one. The victim enters the code, which the attacker captures within seconds, effectively bypassing multi-factor authentication entirely.
From Stolen Credentials to Tokenized Financial Control
What truly distinguishes this new generation of phishing operations from previous iterations is the subsequent actions taken after credentials are compromised. These sophisticated platforms heavily emphasize digital wallet provisioning, a process that enables attackers to load a victim’s payment card onto a device under the attacker’s control. Once the card is tokenized within a digital wallet, it can be utilized for high-value purchases, tap-to-pay transactions, and even cash withdrawals, all without needing the physical card.
One notable example highlighted in the research is a platform named YY Lai Yu, which has been operational since August 2024. This service offers more than 400 phishing templates, targeting users across 119 countries, demonstrating the global reach and adaptability of these operations.
What You Should Do
- Implement FIDO2/WebAuthn Authentication: Adopt stronger, phishing-resistant authentication methods like FIDO2/WebAuthn to prevent real-time interception of one-time passwords and credentials.
- Exercise Extreme Caution with Messaging Apps: Be highly skeptical of unsolicited messages, even if they appear to come from known contacts or legitimate organizations, especially if they contain links or requests for personal information. Verify requests through alternative, trusted communication channels.
- Enable Multi-Factor Authentication (MFA): While not foolproof against these advanced attacks, MFA still adds a crucial layer of security. Prioritize app-based authenticators over SMS-based OTPs where possible.
- Educate Users: Conduct regular training sessions to inform employees and users about the evolving tactics of phishing attacks, particularly those exploiting modern messaging platforms. Emphasize the dangers of clicking unknown links or entering credentials on unverified sites.
- Banks and Financial Institutions: Enhance risk-based verification and device fingerprinting during the digital wallet provisioning process. This makes it significantly harder for attackers to weaponize stolen credentials by loading them onto unauthorized devices.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.