Home Cyber Security

AI, iMessage and Digital Wallet Fraud Driving New Global Phishing Economy: GTIG

A new report from Google Cloud’s Google Threat Intelligence Group (GTIG) has revealed how Chinese-language cybercrime services are rapidly evolving into highly sophisticated global phishing operations powered by AI, encrypted messaging apps, and real-time fraud techniques.

The report details how phishing-as-a-service (PhaaS) operators are increasingly commercialising cybercrime through platforms that allow even low-skilled attackers to launch advanced phishing campaigns against users worldwide.

Researchers said the Chinese-language underground differs significantly from more traditional Russian-speaking cybercrime communities.

While Russian-language phishing groups have historically focused heavily on targeting enterprise customers and large organisations, GTIG found many Chinese-language operators are pursuing more opportunistic campaigns against the general public.

Many operators also appear unusually open about their activities, with some allegedly posting luxury lifestyle photos publicly on Telegram channels used to advertise phishing services.

The report outlines how attackers are increasingly abandoning conventional SMS phishing techniques in favour of encrypted delivery channels including Apple iMessage and Rich Communication Services (RCS).

GTIG warned these encrypted platforms create challenges for traditional telecommunications filtering systems because malicious links are harder to inspect before reaching users.

The attacks themselves are also becoming far more interactive.

Instead of simply stealing passwords, phishing operators now frequently intercept login credentials and one-time passcodes in real time. Attackers can then immediately use the captured information to provision stolen payment cards into digital wallets controlled by criminals.

GTIG researchers also identified increasing use of AI-powered phishing infrastructure.

According to the report, one phishing platform linked to the Darcula PhaaS operation uses AI-generated page builders capable of cloning legitimate websites automatically.

The report said this trend toward “localisation-as-a-service” is helping cybercriminals tailor scams for specific countries and cultures with increasing sophistication.

One example cited in the research, a platform called YY Lai Yu, allegedly supports phishing campaigns in 119 countries and includes highly localised lures targeting Japanese users with fake rewards schemes, utility subsidy scams, and impersonation pages for local financial institutions and online services.

The broader ecosystem reportedly includes services beyond phishing itself, including domain registration, hosting, spam delivery infrastructure, money laundering operations, and stolen payment card trading.

GTIG warned that phishing awareness training alone is unlikely to be sufficient against increasingly automated and AI-enhanced phishing operations.

The group said organisations should consider phishing-resistant authentication technologies such as FIDO2 and WebAuthn, combined with stronger fraud detection and device verification systems.

The findings add to growing concerns around AI-enabled cybercrime globally, as attackers continue adopting automation and advanced social engineering tactics to scale attacks and improve success rates.

For Australian organisations, the report serves as another reminder that phishing campaigns are becoming increasingly difficult to distinguish from legitimate communications, particularly when delivered through trusted messaging platforms and tailored to local user behaviour.