Lucid: Hackers target smartphone users in 88 countries, iPhone also not safe
Lucid: Unlike other traditional SMS phishing, messages sent via iMessage and RCS have a higher delivery rate, as these are E2EE-based services. These messages are much cheaper than SMS, as the mobile operator does not charge them.
This time hackers are targeting mobile users from 88 countries around the world. Usually, users of a single operating system are targeted by hackers, but this time both Android and iPhone are on target. According to security researchers, cybercriminals are sending phishing messages to 88 countries using iPhone and Android smartphones.
They are sent via iMessage and RCS (Rich Communication Services) chat via the 'Lucid' Phishing-as-a-Service (PhaaS) platform with links to phishing sites. Because of end-to-end encryption (E2EE), these messages get easily past traditional SMS spam blockers. Cybercriminals are currently offering licenses of this platform in a Telegram channel so other criminals may also utilize these services.
Unlike other conventional phishing via SMS, iMessage, and RCS-based messages enjoy a greater delivery rate, as these services are based on E2EE. Phishing messages via these services are significantly less expensive than via SMS because these don't attract mobile operator costs. iMessage phishing messages are sent via huge iOS device farms where temporary Apple IDs are employed. Cybercriminals abuse mobile network operator security vulnerabilities to send messages via RCS.