Phishing Services Now Steal Money in Real Time

Chinese-language phishing services are moving past password theft and into live fraud. The standard response of resetting credentials misses the point when attackers can capture a one-time code, bypass MFA in the same session, and push stolen payment data into a tokenized wallet right away. Google Threat Intelligence Group says it reviewed a dozen active PhaaS offerings in the Chinese underground and found a clear shift toward real-time OTP interception, wallet provisioning abuse, and encrypted delivery channels such as RCS and iMessage that avoid SMS filtering. GTIG also says the market is mature and expanding, with provider activity tied into a broader criminal ecosystem. For financial-services teams, the risk is immediate account control and payment theft, not a delayed credential dump. If SMS OTP or wallet provisioning is part of the trust flow, a stolen code can become a live takeover before the session ends.

Part of the PlainSec briefing for 2026-05-27

Sources