Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Home/Threats/RCS and iMessage Phishing Bypasses SMS Security Filters
Threats

RCS and iMessage Phishing Bypasses SMS Security Filters

Key Takeaways Cybercriminals are increasingly using Rich Communication Services (RCS) and Apple iMessage for sophisticated phishing campaigns. These advanced messaging platforms bypass traditional...

Emy Elsamnoudy
Emy Elsamnoudy
May 26, 2026 4 Min Read
65 0

Key Takeaways

  • Cybercriminals are increasingly using Rich Communication Services (RCS) and Apple iMessage for sophisticated phishing campaigns.
  • These advanced messaging platforms bypass traditional SMS security filters due to end-to-end encryption, making detection and blocking more challenging.
  • Phishing-as-a-Service (PhaaS) platforms, particularly those in the Chinese-language underground, are enabling attackers to steal credentials and gain control over victims’ financial accounts, including digital wallet provisioning.
  • The attacks aim for real-time financial control, enabling contactless payments, ATM withdrawals, and fund transfers without direct access to the victim’s physical device.
  • Defenders should implement FIDO2/WebAuthn authentication and banks should enhance risk-based verification during digital wallet provisioning to mitigate these threats.

Sophisticated Phishing Campaigns Exploit RCS and iMessage to Bypass SMS Filters

Cybercriminals are significantly enhancing their phishing operations, leveraging advanced messaging protocols such as Rich Communication Services (RCS) and Apple’s iMessage to circumvent established SMS security measures. This strategic shift represents a critical escalation in how malicious actors target individuals, primarily to pilfer sensitive financial information.

Table Of Content

  • Key Takeaways
  • Sophisticated Phishing Campaigns Exploit RCS and iMessage to Bypass SMS Filters
  • Evolution of Phishing Objectives
  • Phishing Services Exploit Encrypted Messaging
  • From Stolen Credentials to Tokenized Financial Control
  • What You Should Do

A comprehensive report reveals a growing trend in these sophisticated phishing endeavors. Rather than relying on standard SMS messages, which are often easily identified and blocked by carrier-level filters, threat actors are now employing encrypted communication channels like RCS and iMessage to deliver malicious links directly to victims’ mobile devices. This change in methodology marks a substantial advancement in the sophistication of contemporary phishing attacks.

Evolution of Phishing Objectives

The objectives of these cybercriminals have evolved beyond merely stealing usernames and passwords. Their current aim is to achieve complete, real-time control over victims’ financial accounts. This includes the capability to deplete funds, execute contactless payments, and perform ATM withdrawals, all without requiring physical access to the victim’s device. This level of access underscores a dangerous new frontier in financial fraud.

The Google Threat Intelligence Group (GTIG) recently shared a report detailing its analysis of a dozen active Phishing-as-a-Service (PhaaS) platforms operating within the Chinese-language underground. Researchers discovered these platforms to be mature, highly organized services that significantly lower the barrier to entry for aspiring cybercriminals, indicating a broader systemic change in how credential theft is executed at scale.

Historically, Russian-speaking actors have dominated the PhaaS landscape. However, a distinct and rapidly expanding Chinese-language ecosystem has emerged as a formidable competitor. These services are not simply imitations of their Russian counterparts; they function with their own unique organizational structures, target profiles, and internal culture, including threat actors who openly publicize their illicit earnings on platforms like Telegram.

Late last year, Google initiated legal proceedings against a PhaaS provider linked to this burgeoning ecosystem. Concurrently, the company has continued to advocate for legislative action and implement technical safeguards designed to counter these scams. Despite these ongoing efforts, the latest findings indicate that the ecosystem continues to expand and refine its deceptive methods.

Phishing Services Exploit Encrypted Messaging

Traditional SMS phishing, commonly known as smishing, faces increasing scrutiny from carrier-level filters designed to detect and block suspicious links. Chinese-language PhaaS operators have recognized this vulnerability and consequently migrated their delivery infrastructure to RCS and iMessage. A key advantage for attackers is that both protocols utilize end-to-end encryption, which significantly complicates network-level tools’ ability to inspect or block malicious content.

Beyond the technical evasion, these modern messaging platforms offer a more polished and credible user experience compared to basic text messages. They support features such as read receipts, typing indicators, high-resolution images, and group chats. When a phishing message arrives via these channels, its appearance is often convincingly legitimate, making it far more likely for an average user to interact with it. The combination of technical bypass and visual authenticity renders these campaigns exceptionally dangerous.

Once a victim clicks a malicious link and inputs their credentials, the stolen data instantly appears on the attacker’s live administration panel. The attacker then simultaneously triggers a One-Time Password (OTP) request on their own device just as the victim is prompted for one. The victim enters the code, which the attacker captures within seconds, effectively bypassing multi-factor authentication entirely.

From Stolen Credentials to Tokenized Financial Control

What truly distinguishes this new generation of phishing operations from previous iterations is the subsequent actions taken after credentials are compromised. These sophisticated platforms heavily emphasize digital wallet provisioning, a process that enables attackers to load a victim’s payment card onto a device under the attacker’s control. Once the card is tokenized within a digital wallet, it can be utilized for high-value purchases, tap-to-pay transactions, and even cash withdrawals, all without needing the physical card.

One notable example highlighted in the research is a platform named YY Lai Yu, which has been operational since August 2024. This service offers more than 400 phishing templates, targeting users across 119 countries, demonstrating the global reach and adaptability of these operations.

What You Should Do

  • Implement FIDO2/WebAuthn Authentication: Adopt stronger, phishing-resistant authentication methods like FIDO2/WebAuthn to prevent real-time interception of one-time passwords and credentials.
  • Exercise Extreme Caution with Messaging Apps: Be highly skeptical of unsolicited messages, even if they appear to come from known contacts or legitimate organizations, especially if they contain links or requests for personal information. Verify requests through alternative, trusted communication channels.
  • Enable Multi-Factor Authentication (MFA): While not foolproof against these advanced attacks, MFA still adds a crucial layer of security. Prioritize app-based authenticators over SMS-based OTPs where possible.
  • Educate Users: Conduct regular training sessions to inform employees and users about the evolving tactics of phishing attacks, particularly those exploiting modern messaging platforms. Emphasize the dangers of clicking unknown links or entering credentials on unverified sites.
  • Banks and Financial Institutions: Enhance risk-based verification and device fingerprinting during the digital wallet provisioning process. This makes it significantly harder for attackers to weaponize stolen credentials by loading them onto unauthorized devices.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

PuTTY 0.84 Patches High-Severity SSH and Telnet Vulnerabilities

Next Post

EU Fines Google Record €2.1 Billion for DMA Search Violations

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us