Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Google Threat Intelligence Group has documented a maturing Chinese-language phishing-as-a-service ecosystem, led by the Darcula platform (UNC5814), that now intercepts one-time passcodes in real time and converts stolen payment card data directly into mobile wallet tokens, bypassing traditional fraud controls without ever exposing raw card numbers. The campaign targets consumers and financial services customers across 119 countries, with concentrated activity against Japanese financial platforms including Rakuten Securities, Nomura Securities, PayPay, and JCB Card. Organizations relying on SMS-based MFA, static phishing page detection, or IOC blocklists cannot defend against this threat model.

Author

Tech Jacks Solutions