Threats & Adversaries · Credential Theft
Phishing Services Now Steal Money in Real Time Chinese-language phishing services are moving past password theft and into live fraud. The standard response of resetting credentials misses the point when attackers can capture a one-time code, bypass MFA in the same session, and push stolen payment data into a tokenized wallet right away.
Google Threat Intelligence Group says it reviewed a dozen active PhaaS offerings in the Chinese underground and found a clear shift toward real-time OTP interception, wallet provisioning abuse, and encrypted delivery channels such as RCS and iMessage that avoid SMS filtering. GTIG also says the market is mature and expanding, with provider activity tied into a broader criminal ecosystem.
For financial-services teams, the risk is immediate account control and payment theft, not a delayed credential dump. If SMS OTP or wallet provisioning is part of the trust flow, a stolen code can become a live takeover before the session ends.
3 sources · May 26
Timeline Sources May 26 Infosecurity Magazine
Chinese Threat Actors Shift to Live Credential Interception
Almost all organizations impersonated by Chinese phishing platforms are non-Chinese entities, suggesting operators deliberately avoid domestic targets
original May 26 Help Net Security
Chinese phishing gangs grow into a force to be reckoned with - Help Net Security
Chinese-language phishing-as-a-service communities are expanding beyond a market long dominated by Russian-speaking cybercriminals.
original May 25 Mandiant
The Evolution of Chinese-Language Phishing Services | Google Cloud Blog
We highlight rapid growth and key shifts in the Chinese-language phishing-as-a-service (PhaaS) ecosystem.
original Part of the PlainSec briefing for 2026-05-25
Every edition of this story: Phishing Services Now Steal Money in Real Time
More from today
Threats & Adversaries · Credential Theft
Phishing Services Now Steal Money in Real Time Chinese-language phishing services are moving past password theft and into live fraud. The standard response of resetting credentials misses the point when attackers can capture a one-time code, bypass MFA in the same session, and push stolen payment data into a tokenized wallet right away.
Google Threat Intelligence Group says it reviewed a dozen active PhaaS offerings in the Chinese underground and found a clear shift toward real-time OTP interception, wallet provisioning abuse, and encrypted delivery channels such as RCS and iMessage that avoid SMS filtering. GTIG also says the market is mature and expanding, with provider activity tied into a broader criminal ecosystem.
For financial-services teams, the risk is immediate account control and payment theft, not a delayed credential dump. If SMS OTP or wallet provisioning is part of the trust flow, a stolen code can become a live takeover before the session ends.
3 sources · May 26
Timeline Sources May 26 Infosecurity Magazine
Chinese Threat Actors Shift to Live Credential Interception
Almost all organizations impersonated by Chinese phishing platforms are non-Chinese entities, suggesting operators deliberately avoid domestic targets
original May 26 Help Net Security
Chinese phishing gangs grow into a force to be reckoned with - Help Net Security
Chinese-language phishing-as-a-service communities are expanding beyond a market long dominated by Russian-speaking cybercriminals.
original May 25 Mandiant
The Evolution of Chinese-Language Phishing Services | Google Cloud Blog
We highlight rapid growth and key shifts in the Chinese-language phishing-as-a-service (PhaaS) ecosystem.
original Part of the PlainSec briefing for 2026-05-25
Every edition of this story: Phishing Services Now Steal Money in Real Time
More from today