Also known as: changqixinyun, Black Technology, EncryptHub, tracked as, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Matsuo, Yusuke Iwasawa, ALPHV, Royal Ransomware
XinXin emerged as an organized threat actor that specializes in mobile‑messaging phishing (smishing) and traditional email spearphishing. The core of its operation is the Lucid PaaS platform, which allows affiliates to craft bespoke phishing campaigns targeting a global audience via RCS, iMessage, SMS, and email. Through these fronts, XinXin harvests payment card information, personal data, and other credentials with high automation and stealth. The organization also maintains subsidiaries like Lighthouse and Darcula, which expand its catalog of compromised domains and social‑engineering templates. The group has a well‑defined hierarchy that monetizes stolen data while simultaneously providing support for new affiliates to develop their own phishing-as‑a‑service tools. By offering a marketplace for sold credentials and by facilitating the spread of phishing kits, XinXin turns credential theft into a scalable income stream. Operationally, it exploits public-facing services and SMS gateways, often leveraging known RCS and iMessage weaknesses to bypass conventional message‑filtering systems. XinXin’s attacks emphasize low detection risk: the malicious links redirect victims to fake merchant or service portals, capture input fields, and then exfiltrate payloads via HTTP/HTTPS backends. The use of legitimate communication channels makes early detection difficult, while the group’s focus on financial theft—credit card data and PII—ensures a high payoff. The threat actor continues to evolve, adding new phishing kits like Darcula and offering affiliates updates that adapt to changing security controls such as multi‑factor authentication. XinXin remains heavily involved in the underground cybercrime market, supplying both software tools and the resulting compromised data to buyers globally.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
XinXin is a Chinese‑speaking cybercriminal unit that runs a phishing‑as‑a‑service platform called Lucid, using smishing via Rich Communication Services (RCS) and Apple iMessage to bypass SMS filters and harvest credit card details and personal identifiers. The group sells the stolen data through a structured hierarchy and also supports the creation of similar kits such as Lighthouse and Darcula. XinXin targets a wide range of sectors worldwide, focusing on financial gain rather than state objectives.
Goals & Targeting
XinXin’s primary strategic objective is monetary gain through large‑scale credential harvesting. Its extensive use of smishing via RCS/iMessage appeals to victims who trust mobile messaging, allowing it to penetrate a variety of institutions—especially in finance, health care, education, and critical infrastructure—where personal data or payments are routinely processed. The actor deliberately targets countries with substantial mobile usage such as the United States, UK, Germany, Australia, India, and China, but also extends operations into Eastern European states, Middle Eastern nations, and Southeast Asia where regulatory enforcement is comparatively lax. Typical victims include enterprises handling payment card data or sensitive personal information; the organization’s broad sector focus allows XinXin to adapt its messaging vector to each target’s prevalent communication channels.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
XinXin regularly launches multi‑channel phishing campaigns that combine email, RCS, and iMessage vectors. The actor’s operational tempo is high, with new domains and mail templates created at a rapid cadence—estimated hundreds of domains per month—to stay ahead of blacklisting efforts. Victim selection emphasizes organizations in sectors handling payment data or sensitive personal logs; however the group does not discriminate strictly by industry. Notable past operations include large‑scale smishing attacks that compromised thousands of credential sets, which were then sold on underground forums. XinXin’s campaigns exhibit a consistent pattern: initial compromise through a lure, credential capture via fake login portals, exfiltration over encrypted web channels, and subsequent monetization via data marketplaces. The actor frequently updates its phishing kits to evade detection, such as incorporating domain generation algorithms and dynamic script delivery mechanisms. While no public reports link XinXin directly to ransomware operations, the overlap in infrastructure with known RaaS groups suggests a potential future expansion into double‑extortion or data‑theft‑enhanced attacks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment relies heavily on publicly available reports highlighting XinXin’s use of smishing, RCS/iMessage exploitation, and the Lucid phishing‑as‑a‑service platform. While several overlapping technical indicators (e.g., domain-based C2, credential harvesting) are documented across independent sources, direct attribution to specific malware families is lacking, limiting certainty regarding advanced payloads such as ransomware. Consequently, the confidence level is moderate; gaps remain around precise timeline of operations and potential integration with other RaaS groups.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
44
Tools
0
Campaigns
14
IOCs
0
Observed Data
5
Tactics