Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors XinXin

Also known as: changqixinyun, Black Technology, EncryptHub, tracked as, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Matsuo, Yusuke Iwasawa, ALPHV, Royal Ransomware

Description

XinXin emerged as an organized threat actor that specializes in mobile‑messaging phishing (smishing) and traditional email spearphishing. The core of its operation is the Lucid PaaS platform, which allows affiliates to craft bespoke phishing campaigns targeting a global audience via RCS, iMessage, SMS, and email. Through these fronts, XinXin harvests payment card information, personal data, and other credentials with high automation and stealth. The organization also maintains subsidiaries like Lighthouse and Darcula, which expand its catalog of compromised domains and social‑engineering templates. The group has a well‑defined hierarchy that monetizes stolen data while simultaneously providing support for new affiliates to develop their own phishing-as‑a‑service tools. By offering a marketplace for sold credentials and by facilitating the spread of phishing kits, XinXin turns credential theft into a scalable income stream. Operationally, it exploits public-facing services and SMS gateways, often leveraging known RCS and iMessage weaknesses to bypass conventional message‑filtering systems. XinXin’s attacks emphasize low detection risk: the malicious links redirect victims to fake merchant or service portals, capture input fields, and then exfiltrate payloads via HTTP/HTTPS backends. The use of legitimate communication channels makes early detection difficult, while the group’s focus on financial theft—credit card data and PII—ensures a high payoff. The threat actor continues to evolve, adding new phishing kits like Darcula and offering affiliates updates that adapt to changing security controls such as multi‑factor authentication. XinXin remains heavily involved in the underground cybercrime market, supplying both software tools and the resulting compromised data to buyers globally.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Healthcare
Government
Education
Telecommunications
Manufacturing
Critical infrastructure
Media
Retail
Non profit
Information technology
Hospitality
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation

Targeted Countries / Regions

CN
RU
TW
IR
IN
UA
GB
DE
KP
PK
BY
PL
CA
AU
SG

AI Analysis

Grounded in web research
· 3 hours ago

Executive Summary

XinXin is a Chinese‑speaking cybercriminal unit that runs a phishing‑as‑a‑service platform called Lucid, using smishing via Rich Communication Services (RCS) and Apple iMessage to bypass SMS filters and harvest credit card details and personal identifiers. The group sells the stolen data through a structured hierarchy and also supports the creation of similar kits such as Lighthouse and Darcula. XinXin targets a wide range of sectors worldwide, focusing on financial gain rather than state objectives.

Goals & Targeting

XinXin’s primary strategic objective is monetary gain through large‑scale credential harvesting. Its extensive use of smishing via RCS/iMessage appeals to victims who trust mobile messaging, allowing it to penetrate a variety of institutions—especially in finance, health care, education, and critical infrastructure—where personal data or payments are routinely processed. The actor deliberately targets countries with substantial mobile usage such as the United States, UK, Germany, Australia, India, and China, but also extends operations into Eastern European states, Middle Eastern nations, and Southeast Asia where regulatory enforcement is comparatively lax. Typical victims include enterprises handling payment card data or sensitive personal information; the organization’s broad sector focus allows XinXin to adapt its messaging vector to each target’s prevalent communication channels.

Enhanced Description

Key Capabilities

  • Phishing-as-a-service platform (Lucid)
  • Smishing via Rich Communication Services (RCS) and Apple iMessage
  • Custom phishing kits (Lighthouse, Darcula)
  • Credential harvesting of credit card details and personal identifiers
  • Automated mass‑phishing campaign generation
  • Staged infrastructure for command & control
  • Marketplace for selling stolen credentials
  • Support for development of similar PhaaS services
  • Exfiltration over HTTPS/web services

MITRE ATT&CK Tactics

Initial Access
Resource Development
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1566.001 (Phish Email)
T1566.002 (Social Engineering)
T1190 (Exploit Public-Facing Application)
T1133 (External Remote Services)
T1048 (Exfiltration Over Alternative Protocol)
T1567 (Exfiltration Over Web Service)
T1657 (Financial Theft)

Software / Tooling

Lucid PhaaS platform
Lighthouse phishing kit
Darcula phishing kit
Various custom phishing emails and SMS templates

Campaigns & Victims

XinXin regularly launches multi‑channel phishing campaigns that combine email, RCS, and iMessage vectors. The actor’s operational tempo is high, with new domains and mail templates created at a rapid cadence—estimated hundreds of domains per month—to stay ahead of blacklisting efforts. Victim selection emphasizes organizations in sectors handling payment data or sensitive personal logs; however the group does not discriminate strictly by industry. Notable past operations include large‑scale smishing attacks that compromised thousands of credential sets, which were then sold on underground forums. XinXin’s campaigns exhibit a consistent pattern: initial compromise through a lure, credential capture via fake login portals, exfiltration over encrypted web channels, and subsequent monetization via data marketplaces. The actor frequently updates its phishing kits to evade detection, such as incorporating domain generation algorithms and dynamic script delivery mechanisms. While no public reports link XinXin directly to ransomware operations, the overlap in infrastructure with known RaaS groups suggests a potential future expansion into double‑extortion or data‑theft‑enhanced attacks.

IOC Patterns

  • Spearphishing emails containing malicious links Smishing messages using RCS/iMessage and SMS Domains generated via algorithmic pattern for C2 Credential harvesting landing pages mimicking legitimate merchant portals Exfiltration over HTTPS/HTTP Use of custom domains that frequently change Phishing kits delivered via encrypted mail attachments

Recommended Actions

  • Deploy comprehensive mobile-security solutions that filter RCS and iMessage traffic for malicious links. Enforce multi‑factor authentication on all payment card processing endpoints. Educate staff to recognize smishing; conduct regular training simulations. Implement advanced phishing detection engines with zero‑trust email gateways. Block known malicious domains via network security appliances. Monitor outbound HTTPS traffic for anomalous exfiltration patterns. Maintain up‑to‑date threat intelligence feeds focusing on PhaaS and smishing trends.

Suggested Tags

cybercrime
phishing
smishing
credential theft
financial fraud
PhaaS

Confidence Assessment

The assessment relies heavily on publicly available reports highlighting XinXin’s use of smishing, RCS/iMessage exploitation, and the Lucid phishing‑as‑a‑service platform. While several overlapping technical indicators (e.g., domain-based C2, credential harvesting) are documented across independent sources, direct attribution to specific malware families is lacking, limiting certainty regarding advanced payloads such as ransomware. Consequently, the confidence level is moderate; gaps remain around precise timeline of operations and potential integration with other RaaS groups.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  2. arxiv.org — Cited by web research for: Matsuo
  3. www.huntress.com — Cited by web research for: Dark
  4. www.uscc.gov — Cited by web research for: Kevin
  5. https://thehackernews.com/2025/09/17500-phishing-domains-target-316.html — Cited by AI analysis.

Intel Summary

13

Techniques

44

Tools

0

Campaigns

14

IOCs

0

Observed Data

5

Tactics

Tags

Phishing
Data Exfiltration
cybercrime
phishing
smishing
credential theft
financial fraud
PhaaS

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.