Chinese Threat Actors Shift to Live Credential Interception in Phishing Campaigns (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Live admin panels capture OTPs in real-time to bypass MFA
- Phishing lures distributed via encrypted messaging (RCS, iMessage)
- AI-generated unique phishing pages evade signature detection
"Google Threat Intelligence Group reports that Chinese PhaaS operators have moved from static password harvesting to real-time credential interception using live admin panels. They intercept OTPs to bypass MFA. Lures are delivered via encrypted messaging (RCS, iMessage). Nearly all impersonated entities are non-Chinese, targeting Japan, US, Australia, Hong Kong, and UAE. Some platforms use AI to generate unique phishing pages and provision digital wallets for monetization."
#Live Credential Interception
#Encrypted Messaging Phishing
#AI Phishing
no comments yet.