TL;DR
Chinese-language phishing-as-a-service (PhaaS) platforms—criminal marketplaces selling phishing tools—have grown rapidly but remained understudied compared to Russian equivalents. Google Threat Intelligence Group analyzed a dozen active Chinese PhaaS services and discovered they evolved from static password theft to real-time one-time passcode (OTP) interception, bypassing multifactor authentication and targeting digital wallet tokenization.
✦ Why It Matters
Engineers must implement real-time OTP validation, encrypted channel monitoring, and wallet tokenization safeguards against evolving PhaaS threats.
Key Takeaways
How It Works
Chinese-language PhaaS operators utilize real-time interception by capturing OTPs as victims enter them, allowing attackers to bypass multifactor authentication instantly. They also exploit digital wallets by tokenizing stolen payment data, enabling high-value transactions.
Related