Netcraft researchers have uncovered two large-scale phishing campaigns linked to the Lucid and Lighthouse Phishing-as-a-Service (PhaaS) platforms, enabling cybercriminals to impersonate hundreds of global companies.
Since identifying the campaigns, analysts have detected over 17,500 phishing domains targeting 316 brands across 74 countries, underscoring the growing industrialization of cybercrime through subscription-based phishing services.
Lucid: Sophisticated Anti-Monitoring and Global Reach
The Lucid PhaaS platform has emerged as a major contributor to the surge in phishing, with campaigns impersonating toll services, governments, postal operators, and financial institutions worldwide.
Netcraft identified phishing URLs tied to 164 brands in 63 countries, each built with unique templates and themes to appear convincing.

Lucid distinguishes itself through advanced anti-monitoring controls designed to prevent exposure by researchers or security tools. Fraudulent pages require specific access conditions before rendering payloads, such as:
- A valid path parameter (e.g., “/servicios”) configured by attackers to reveal phishing content.
- Connection via a required proxy country, forcing targeted geolocation.
- A mobile browser user-agent, concealing pages from desktop monitors.
When criteria are not met, victims are redirected to benign “fake shop” templates, such as counterfeit clothing or shoe stores, which mask active campaigns. This systemic obfuscation complicates automated detection and takedown efforts.
Netcraft observed significant overlap between Lucid and Lighthouse operations, particularly through near-identical anti-monitoring landing pages. Investigators deployed targeted automation techniques to detect hidden Lucid URLs more effectively.
Lighthouse: 2FA Theft and Criminal Affiliations
The Lighthouse platform, created by developer WangDuoYu, mirrors Lucid’s tactics while focusing on multi-factor credential theft. Sold via subscription, Lighthouse kits range from $88 per week to $1,588 annually, offering continuously updated phishing templates.
Campaigns linked to Lighthouse display heavy HTML obfuscation and customized brand impersonations, with activity detected against 204 brands in 50 countries.
During investigations, researchers discovered identical templates between Lighthouse-hosted phishing and its sales materials, confirming attribution.
Notably, infrastructure tied to Lighthouse, such as the test-24[.]top domain used in demo videos links to other PhaaS groups, including Haozi, previously implicated in facilitating over $280,000 in criminal transactions.
Shared Telegram group memberships further suggest cross-group collaboration within the PhaaS ecosystem.
Both Lighthouse and Lucid employed the same ‘LOAFING OUT LOUD’ fake shop disguise for anti-monitoring, reinforcing the connection between the two platforms despite code variances.
Lowering the Barrier to Cybercrime
The rise of PhaaS platforms like Lucid and Lighthouse reflects a broader trend: cybercriminals no longer need advanced coding skills to launch large-scale campaigns. These kits bundle phishing templates, evasion technologies, and even support services into turnkey packages.

In June 2025 alone, 13.5% of all phishing hostnames detected by Netcraft were powered by PhaaS frameworks. The exponential growth underscores how the “commoditization” of phishing lowers technical barriers while expanding the scale of fraud.
By correlating infrastructure, monitoring kit evolution, and deploying automation, Netcraft aims to hinder these ecosystems. However, as PhaaS operators refine their deception techniques, defenders face mounting challenges in disruption and brand protection.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates