{"id":13152,"date":"2026-05-26T10:03:47","date_gmt":"2026-05-26T10:03:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/26\/phishing-services-use-rcs-and-imessage-to-bypass-traditional-sms-security-filters\/"},"modified":"2026-05-26T10:03:47","modified_gmt":"2026-05-26T10:03:47","slug":"phishing-services-use-rcs-and-imessage-to-bypass-traditional-sms-security-filters","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/26\/phishing-services-use-rcs-and-imessage-to-bypass-traditional-sms-security-filters\/","title":{"rendered":"Phishing Services Use RCS and iMessage to Bypass Traditional SMS Security Filters"},"content":{"rendered":"<p>    Phishing Services Use RCS and iMessage to Bypass Traditional SMS Security Filters<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A new wave of phishing operations is quietly changing the way cybercriminals steal financial data from everyday people. <\/p>\n<p class=\"wp-block-paragraph\">Rather than relying on traditional SMS messages that carriers can easily flag and block, threat actors are now using encrypted messaging channels like Rich Communication Services (RCS) and Apple iMessage to deliver malicious links directly to victims\u2019 phones.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/a5d6e8cf-ead9-403e-b9c3-65529f0d00e0\/Phishing-Services-Use-RCS-and-iMessage-to-Bypass-Traditional-SMS-Security-Filters.pdf?AWSAccessKeyId=ASIA2F3EMEYEX6LT542O&amp;Signature=Jlcmln3UyY5DsaIpiCPPefTc4QY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjELD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBtI89LgxZ6uqNh6T%2BpNqgER0Kcq9WLqoJ0UH38LEBdMAiEAionb9CbnbEq7pWmSlmRu90mkBZuNLUP0rFv7UAzK15Iq8wQIeRABGgw2OTk3NTMzMDk3MDUiDIRiSxNkhsX6fsWuWCrQBKZExNsIgj%2F3PVzaUKL6gtZlmDUESf%2FY%2F3g%2BjN0jcBAzniqh8VSEqhee0iUtSxAvRp4tByxD4McWPlrGE3hLKHAlkpjaT%2BDbKSTckjZZW6%2FSOPMHWAwcopLxmYrLwRKOOMA7UyeKxln9W1Ml8dIUWbAJrsU9vPpz98%2BCdwwudpntoL4hp6ewNSFzisvZp6zMVrbRGlizv3xkd5IWxrWmIZGdaUyzpDiVl57dW%2F5AtSF5D2mBBQljRLCMh9mfsxhzjmBIw%2FceHQRpvdYaVAtt80g%2BYOMYbQdQfAIQySWnjdIVF%2B54pUfIebzrRhfnjEua%2BkcVbU3t6cXdOOOTDzDxcbkr35gnKZUtPjW%2BQ1xC7e7E6%2FzRY4cW6ZaQigCmZe7glOxfhYcogrqbZS4bUk9Hb2DBpSlGycPxcxVh1UJNMQuGKbkqTkdvwad8ZXcIY%2FPCHQKOYw06LmmVAKyaQklvTXrJzW6pYygBWvh5qRY1qxZ6JSwgfRq6BQS22viL%2BCPUBr6dzlmqkjZHVTIv%2Ft7sjqlZRvJBuDTbpp04dOqN48Tt%2BB2B8pn8GkMiLHUbBM7erLZUOo9xvYuhXDLFPCii2yh%2FJJ094dM%2F6SjTS8qy8YJQN6p%2BaeL4W%2FlW4Krfp0y7RDO7QVtYClGIs2iAlKwzh373U05b%2B02p2GN4Ph4Lt6eKF%2BtkuXZogwM1WhcFtgFfHuYHDuLDlb6cf16hy3qnAmSIlaQD1DCgf1yujbQ4jC6aoVzIc%2B2slzjXDprA2OF7XQgoSe0mJV2AAesMB%2B0LlQIwrZbV0AY6mAEloZfmx30f4OVq9ZllgDWX8jzRcuvmh9HYxBEc8h%2BY6OKOYr%2BmnsoFvXkcvv%2BTt%2FEfu5ERIF4o9PpDHQ1iDbSipEr1ukfn11QyxZZ8bWTq0lHF%2FvKF6M2G7FUm78e40xX%2FAIsQkR7kv%2FnlWU1nqX3b6vxLSjYLqy%2F8AMXmXBG1g98VpHMrtpuDVIu%2BQHEJLDZ66Iq25Q4hMg%3D%3D&amp;Expires=1779782614\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">This shift marks a significant step forward in the sophistication of phishing attacks. Cybercriminals are no longer just after usernames and passwords. <\/p>\n<p class=\"wp-block-paragraph\">Their goal has evolved to gaining full, real-time control over victims\u2019 financial accounts, including the ability to drain funds, make contactless payments, and conduct ATM withdrawals, all from a device the victim never touches.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/a5d6e8cf-ead9-403e-b9c3-65529f0d00e0\/Phishing-Services-Use-RCS-and-iMessage-to-Bypass-Traditional-SMS-Security-Filters.pdf?AWSAccessKeyId=ASIA2F3EMEYEX6LT542O&amp;Signature=Jlcmln3UyY5DsaIpiCPPefTc4QY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjELD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBtI89LgxZ6uqNh6T%2BpNqgER0Kcq9WLqoJ0UH38LEBdMAiEAionb9CbnbEq7pWmSlmRu90mkBZuNLUP0rFv7UAzK15Iq8wQIeRABGgw2OTk3NTMzMDk3MDUiDIRiSxNkhsX6fsWuWCrQBKZExNsIgj%2F3PVzaUKL6gtZlmDUESf%2FY%2F3g%2BjN0jcBAzniqh8VSEqhee0iUtSxAvRp4tByxD4McWPlrGE3hLKHAlkpjaT%2BDbKSTckjZZW6%2FSOPMHWAwcopLxmYrLwRKOOMA7UyeKxln9W1Ml8dIUWbAJrsU9vPpz98%2BCdwwudpntoL4hp6ewNSFzisvZp6zMVrbRGlizv3xkd5IWxrWmIZGdaUyzpDiVl57dW%2F5AtSF5D2mBBQljRLCMh9mfsxhzjmBIw%2FceHQRpvdYaVAtt80g%2BYOMYbQdQfAIQySWnjdIVF%2B54pUfIebzrRhfnjEua%2BkcVbU3t6cXdOOOTDzDxcbkr35gnKZUtPjW%2BQ1xC7e7E6%2FzRY4cW6ZaQigCmZe7glOxfhYcogrqbZS4bUk9Hb2DBpSlGycPxcxVh1UJNMQuGKbkqTkdvwad8ZXcIY%2FPCHQKOYw06LmmVAKyaQklvTXrJzW6pYygBWvh5qRY1qxZ6JSwgfRq6BQS22viL%2BCPUBr6dzlmqkjZHVTIv%2Ft7sjqlZRvJBuDTbpp04dOqN48Tt%2BB2B8pn8GkMiLHUbBM7erLZUOo9xvYuhXDLFPCii2yh%2FJJ094dM%2F6SjTS8qy8YJQN6p%2BaeL4W%2FlW4Krfp0y7RDO7QVtYClGIs2iAlKwzh373U05b%2B02p2GN4Ph4Lt6eKF%2BtkuXZogwM1WhcFtgFfHuYHDuLDlb6cf16hy3qnAmSIlaQD1DCgf1yujbQ4jC6aoVzIc%2B2slzjXDprA2OF7XQgoSe0mJV2AAesMB%2B0LlQIwrZbV0AY6mAEloZfmx30f4OVq9ZllgDWX8jzRcuvmh9HYxBEc8h%2BY6OKOYr%2BmnsoFvXkcvv%2BTt%2FEfu5ERIF4o9PpDHQ1iDbSipEr1ukfn11QyxZZ8bWTq0lHF%2FvKF6M2G7FUm78e40xX%2FAIsQkR7kv%2FnlWU1nqX3b6vxLSjYLqy%2F8AMXmXBG1g98VpHMrtpuDVIu%2BQHEJLDZ66Iq25Q4hMg%3D%3D&amp;Expires=1779782614\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/chinese-language-phishing-services\/\" id=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/chinese-language-phishing-services\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google Threat Intelligence Group (GTIG)\u00a0said in a report<\/a> shared with Cyber Security News (CSN)\u00a0that it analyzed a dozen active phishing-as-a-service (PhaaS) platforms operating within the Chinese-language underground. <\/p>\n<p class=\"wp-block-paragraph\">Researchers found these platforms to be mature, well-organized services that are lowering the barrier to entry for cybercriminals and revealing broader shifts in how credential theft is carried out at scale.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/a5d6e8cf-ead9-403e-b9c3-65529f0d00e0\/Phishing-Services-Use-RCS-and-iMessage-to-Bypass-Traditional-SMS-Security-Filters.pdf?AWSAccessKeyId=ASIA2F3EMEYEX6LT542O&amp;Signature=Jlcmln3UyY5DsaIpiCPPefTc4QY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjELD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBtI89LgxZ6uqNh6T%2BpNqgER0Kcq9WLqoJ0UH38LEBdMAiEAionb9CbnbEq7pWmSlmRu90mkBZuNLUP0rFv7UAzK15Iq8wQIeRABGgw2OTk3NTMzMDk3MDUiDIRiSxNkhsX6fsWuWCrQBKZExNsIgj%2F3PVzaUKL6gtZlmDUESf%2FY%2F3g%2BjN0jcBAzniqh8VSEqhee0iUtSxAvRp4tByxD4McWPlrGE3hLKHAlkpjaT%2BDbKSTckjZZW6%2FSOPMHWAwcopLxmYrLwRKOOMA7UyeKxln9W1Ml8dIUWbAJrsU9vPpz98%2BCdwwudpntoL4hp6ewNSFzisvZp6zMVrbRGlizv3xkd5IWxrWmIZGdaUyzpDiVl57dW%2F5AtSF5D2mBBQljRLCMh9mfsxhzjmBIw%2FceHQRpvdYaVAtt80g%2BYOMYbQdQfAIQySWnjdIVF%2B54pUfIebzrRhfnjEua%2BkcVbU3t6cXdOOOTDzDxcbkr35gnKZUtPjW%2BQ1xC7e7E6%2FzRY4cW6ZaQigCmZe7glOxfhYcogrqbZS4bUk9Hb2DBpSlGycPxcxVh1UJNMQuGKbkqTkdvwad8ZXcIY%2FPCHQKOYw06LmmVAKyaQklvTXrJzW6pYygBWvh5qRY1qxZ6JSwgfRq6BQS22viL%2BCPUBr6dzlmqkjZHVTIv%2Ft7sjqlZRvJBuDTbpp04dOqN48Tt%2BB2B8pn8GkMiLHUbBM7erLZUOo9xvYuhXDLFPCii2yh%2FJJ094dM%2F6SjTS8qy8YJQN6p%2BaeL4W%2FlW4Krfp0y7RDO7QVtYClGIs2iAlKwzh373U05b%2B02p2GN4Ph4Lt6eKF%2BtkuXZogwM1WhcFtgFfHuYHDuLDlb6cf16hy3qnAmSIlaQD1DCgf1yujbQ4jC6aoVzIc%2B2slzjXDprA2OF7XQgoSe0mJV2AAesMB%2B0LlQIwrZbV0AY6mAEloZfmx30f4OVq9ZllgDWX8jzRcuvmh9HYxBEc8h%2BY6OKOYr%2BmnsoFvXkcvv%2BTt%2FEfu5ERIF4o9PpDHQ1iDbSipEr1ukfn11QyxZZ8bWTq0lHF%2FvKF6M2G7FUm78e40xX%2FAIsQkR7kv%2FnlWU1nqX3b6vxLSjYLqy%2F8AMXmXBG1g98VpHMrtpuDVIu%2BQHEJLDZ66Iq25Q4hMg%3D%3D&amp;Expires=1779782614\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">While Russian-speaking actors have historically led the PhaaS space, a distinct and fast-growing Chinese-language ecosystem has emerged to rival it. These services do not simply mirror what their Russian counterparts have built. <\/p>\n<p class=\"wp-block-paragraph\">They operate with their own structure, their own targets, and their own culture, including threat actors who openly post about their criminal earnings on Telegram.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/a5d6e8cf-ead9-403e-b9c3-65529f0d00e0\/Phishing-Services-Use-RCS-and-iMessage-to-Bypass-Traditional-SMS-Security-Filters.pdf?AWSAccessKeyId=ASIA2F3EMEYEX6LT542O&amp;Signature=Jlcmln3UyY5DsaIpiCPPefTc4QY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjELD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBtI89LgxZ6uqNh6T%2BpNqgER0Kcq9WLqoJ0UH38LEBdMAiEAionb9CbnbEq7pWmSlmRu90mkBZuNLUP0rFv7UAzK15Iq8wQIeRABGgw2OTk3NTMzMDk3MDUiDIRiSxNkhsX6fsWuWCrQBKZExNsIgj%2F3PVzaUKL6gtZlmDUESf%2FY%2F3g%2BjN0jcBAzniqh8VSEqhee0iUtSxAvRp4tByxD4McWPlrGE3hLKHAlkpjaT%2BDbKSTckjZZW6%2FSOPMHWAwcopLxmYrLwRKOOMA7UyeKxln9W1Ml8dIUWbAJrsU9vPpz98%2BCdwwudpntoL4hp6ewNSFzisvZp6zMVrbRGlizv3xkd5IWxrWmIZGdaUyzpDiVl57dW%2F5AtSF5D2mBBQljRLCMh9mfsxhzjmBIw%2FceHQRpvdYaVAtt80g%2BYOMYbQdQfAIQySWnjdIVF%2B54pUfIebzrRhfnjEua%2BkcVbU3t6cXdOOOTDzDxcbkr35gnKZUtPjW%2BQ1xC7e7E6%2FzRY4cW6ZaQigCmZe7glOxfhYcogrqbZS4bUk9Hb2DBpSlGycPxcxVh1UJNMQuGKbkqTkdvwad8ZXcIY%2FPCHQKOYw06LmmVAKyaQklvTXrJzW6pYygBWvh5qRY1qxZ6JSwgfRq6BQS22viL%2BCPUBr6dzlmqkjZHVTIv%2Ft7sjqlZRvJBuDTbpp04dOqN48Tt%2BB2B8pn8GkMiLHUbBM7erLZUOo9xvYuhXDLFPCii2yh%2FJJ094dM%2F6SjTS8qy8YJQN6p%2BaeL4W%2FlW4Krfp0y7RDO7QVtYClGIs2iAlKwzh373U05b%2B02p2GN4Ph4Lt6eKF%2BtkuXZogwM1WhcFtgFfHuYHDuLDlb6cf16hy3qnAmSIlaQD1DCgf1yujbQ4jC6aoVzIc%2B2slzjXDprA2OF7XQgoSe0mJV2AAesMB%2B0LlQIwrZbV0AY6mAEloZfmx30f4OVq9ZllgDWX8jzRcuvmh9HYxBEc8h%2BY6OKOYr%2BmnsoFvXkcvv%2BTt%2FEfu5ERIF4o9PpDHQ1iDbSipEr1ukfn11QyxZZ8bWTq0lHF%2FvKF6M2G7FUm78e40xX%2FAIsQkR7kv%2FnlWU1nqX3b6vxLSjYLqy%2F8AMXmXBG1g98VpHMrtpuDVIu%2BQHEJLDZ66Iq25Q4hMg%3D%3D&amp;Expires=1779782614\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">Late last year, <a href=\"https:\/\/cybersecuritynews.com\/new-voidproxy-phaas-service\/\" id=\"126121\" target=\"_blank\" rel=\"noreferrer noopener\">Google took legal action against one PhaaS provider tied to this ecosystem<\/a>. Since then, the company has continued pushing for legislation and working to implement technical safeguards against these scams. <\/p>\n<p class=\"wp-block-paragraph\">The findings released today show that despite these efforts, the ecosystem continues to grow and refine its methods.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/a5d6e8cf-ead9-403e-b9c3-65529f0d00e0\/Phishing-Services-Use-RCS-and-iMessage-to-Bypass-Traditional-SMS-Security-Filters.pdf?AWSAccessKeyId=ASIA2F3EMEYEX6LT542O&amp;Signature=Jlcmln3UyY5DsaIpiCPPefTc4QY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjELD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBtI89LgxZ6uqNh6T%2BpNqgER0Kcq9WLqoJ0UH38LEBdMAiEAionb9CbnbEq7pWmSlmRu90mkBZuNLUP0rFv7UAzK15Iq8wQIeRABGgw2OTk3NTMzMDk3MDUiDIRiSxNkhsX6fsWuWCrQBKZExNsIgj%2F3PVzaUKL6gtZlmDUESf%2FY%2F3g%2BjN0jcBAzniqh8VSEqhee0iUtSxAvRp4tByxD4McWPlrGE3hLKHAlkpjaT%2BDbKSTckjZZW6%2FSOPMHWAwcopLxmYrLwRKOOMA7UyeKxln9W1Ml8dIUWbAJrsU9vPpz98%2BCdwwudpntoL4hp6ewNSFzisvZp6zMVrbRGlizv3xkd5IWxrWmIZGdaUyzpDiVl57dW%2F5AtSF5D2mBBQljRLCMh9mfsxhzjmBIw%2FceHQRpvdYaVAtt80g%2BYOMYbQdQfAIQySWnjdIVF%2B54pUfIebzrRhfnjEua%2BkcVbU3t6cXdOOOTDzDxcbkr35gnKZUtPjW%2BQ1xC7e7E6%2FzRY4cW6ZaQigCmZe7glOxfhYcogrqbZS4bUk9Hb2DBpSlGycPxcxVh1UJNMQuGKbkqTkdvwad8ZXcIY%2FPCHQKOYw06LmmVAKyaQklvTXrJzW6pYygBWvh5qRY1qxZ6JSwgfRq6BQS22viL%2BCPUBr6dzlmqkjZHVTIv%2Ft7sjqlZRvJBuDTbpp04dOqN48Tt%2BB2B8pn8GkMiLHUbBM7erLZUOo9xvYuhXDLFPCii2yh%2FJJ094dM%2F6SjTS8qy8YJQN6p%2BaeL4W%2FlW4Krfp0y7RDO7QVtYClGIs2iAlKwzh373U05b%2B02p2GN4Ph4Lt6eKF%2BtkuXZogwM1WhcFtgFfHuYHDuLDlb6cf16hy3qnAmSIlaQD1DCgf1yujbQ4jC6aoVzIc%2B2slzjXDprA2OF7XQgoSe0mJV2AAesMB%2B0LlQIwrZbV0AY6mAEloZfmx30f4OVq9ZllgDWX8jzRcuvmh9HYxBEc8h%2BY6OKOYr%2BmnsoFvXkcvv%2BTt%2FEfu5ERIF4o9PpDHQ1iDbSipEr1ukfn11QyxZZ8bWTq0lHF%2FvKF6M2G7FUm78e40xX%2FAIsQkR7kv%2FnlWU1nqX3b6vxLSjYLqy%2F8AMXmXBG1g98VpHMrtpuDVIu%2BQHEJLDZ66Iq25Q4hMg%3D%3D&amp;Expires=1779782614\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-phishing-services-use-rcs-and-imessage\" class=\"wp-block-heading\"><strong>Phishing Services Use RCS and iMessage<\/strong><\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cybersecuritynews.com\/imessage-smishing-attack\/\" id=\"88486\" target=\"_blank\" rel=\"noreferrer noopener\">Traditional SMS phishing, also known as smishing<\/a>, is increasingly being blocked by carrier-level filters that scan messages for suspicious links. <\/p>\n<p class=\"wp-block-paragraph\">Chinese-language PhaaS operators recognized this limitation and moved their delivery infrastructure to RCS and iMessage instead. Because both protocols use end-to-end encryption, it becomes much harder for network-level tools to inspect or block the malicious content being sent.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/a5d6e8cf-ead9-403e-b9c3-65529f0d00e0\/Phishing-Services-Use-RCS-and-iMessage-to-Bypass-Traditional-SMS-Security-Filters.pdf?AWSAccessKeyId=ASIA2F3EMEYEX6LT542O&amp;Signature=Jlcmln3UyY5DsaIpiCPPefTc4QY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjELD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBtI89LgxZ6uqNh6T%2BpNqgER0Kcq9WLqoJ0UH38LEBdMAiEAionb9CbnbEq7pWmSlmRu90mkBZuNLUP0rFv7UAzK15Iq8wQIeRABGgw2OTk3NTMzMDk3MDUiDIRiSxNkhsX6fsWuWCrQBKZExNsIgj%2F3PVzaUKL6gtZlmDUESf%2FY%2F3g%2BjN0jcBAzniqh8VSEqhee0iUtSxAvRp4tByxD4McWPlrGE3hLKHAlkpjaT%2BDbKSTckjZZW6%2FSOPMHWAwcopLxmYrLwRKOOMA7UyeKxln9W1Ml8dIUWbAJrsU9vPpz98%2BCdwwudpntoL4hp6ewNSFzisvZp6zMVrbRGlizv3xkd5IWxrWmIZGdaUyzpDiVl57dW%2F5AtSF5D2mBBQljRLCMh9mfsxhzjmBIw%2FceHQRpvdYaVAtt80g%2BYOMYbQdQfAIQySWnjdIVF%2B54pUfIebzrRhfnjEua%2BkcVbU3t6cXdOOOTDzDxcbkr35gnKZUtPjW%2BQ1xC7e7E6%2FzRY4cW6ZaQigCmZe7glOxfhYcogrqbZS4bUk9Hb2DBpSlGycPxcxVh1UJNMQuGKbkqTkdvwad8ZXcIY%2FPCHQKOYw06LmmVAKyaQklvTXrJzW6pYygBWvh5qRY1qxZ6JSwgfRq6BQS22viL%2BCPUBr6dzlmqkjZHVTIv%2Ft7sjqlZRvJBuDTbpp04dOqN48Tt%2BB2B8pn8GkMiLHUbBM7erLZUOo9xvYuhXDLFPCii2yh%2FJJ094dM%2F6SjTS8qy8YJQN6p%2BaeL4W%2FlW4Krfp0y7RDO7QVtYClGIs2iAlKwzh373U05b%2B02p2GN4Ph4Lt6eKF%2BtkuXZogwM1WhcFtgFfHuYHDuLDlb6cf16hy3qnAmSIlaQD1DCgf1yujbQ4jC6aoVzIc%2B2slzjXDprA2OF7XQgoSe0mJV2AAesMB%2B0LlQIwrZbV0AY6mAEloZfmx30f4OVq9ZllgDWX8jzRcuvmh9HYxBEc8h%2BY6OKOYr%2BmnsoFvXkcvv%2BTt%2FEfu5ERIF4o9PpDHQ1iDbSipEr1ukfn11QyxZZ8bWTq0lHF%2FvKF6M2G7FUm78e40xX%2FAIsQkR7kv%2FnlWU1nqX3b6vxLSjYLqy%2F8AMXmXBG1g98VpHMrtpuDVIu%2BQHEJLDZ66Iq25Q4hMg%3D%3D&amp;Expires=1779782614\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">These messaging platforms also look and feel far more polished than a basic text message. They support read receipts, typing indicators, high-resolution images, and group chats. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh7Tl32gvmEnA44nftKGeW85oqZXbsMnGNJ0T8_JvNeB6XmfTwFAzwwapkMFNnjUTGRSpjOVEy1_oIUr0zpIBt_cyTQ91OE9-QyM19yVLUuI5NjRCJPMjdenWegpFCmZMLJG04bKMIGQgbRNvArRjDDM_mMhjmtyEUT4309ASTxF877DzmZJcrFa_lP9BY\/s16000\/Phishing%2520site%2520chain%2520%28Source%2520-%2520Google%2520Cloud%29.webp?ssl=1\" alt=\"Phishing site chain (Source - Google Cloud)\"><figcaption class=\"wp-element-caption\">Phishing site chain (Source \u2013 Google Cloud)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">When a phishing message arrives through one of these channels, it looks convincingly real, which makes the average user far more likely to interact with it. The combination of technical evasion and visual legitimacy makes these campaigns particularly dangerous.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/a5d6e8cf-ead9-403e-b9c3-65529f0d00e0\/Phishing-Services-Use-RCS-and-iMessage-to-Bypass-Traditional-SMS-Security-Filters.pdf?AWSAccessKeyId=ASIA2F3EMEYEX6LT542O&amp;Signature=Jlcmln3UyY5DsaIpiCPPefTc4QY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjELD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBtI89LgxZ6uqNh6T%2BpNqgER0Kcq9WLqoJ0UH38LEBdMAiEAionb9CbnbEq7pWmSlmRu90mkBZuNLUP0rFv7UAzK15Iq8wQIeRABGgw2OTk3NTMzMDk3MDUiDIRiSxNkhsX6fsWuWCrQBKZExNsIgj%2F3PVzaUKL6gtZlmDUESf%2FY%2F3g%2BjN0jcBAzniqh8VSEqhee0iUtSxAvRp4tByxD4McWPlrGE3hLKHAlkpjaT%2BDbKSTckjZZW6%2FSOPMHWAwcopLxmYrLwRKOOMA7UyeKxln9W1Ml8dIUWbAJrsU9vPpz98%2BCdwwudpntoL4hp6ewNSFzisvZp6zMVrbRGlizv3xkd5IWxrWmIZGdaUyzpDiVl57dW%2F5AtSF5D2mBBQljRLCMh9mfsxhzjmBIw%2FceHQRpvdYaVAtt80g%2BYOMYbQdQfAIQySWnjdIVF%2B54pUfIebzrRhfnjEua%2BkcVbU3t6cXdOOOTDzDxcbkr35gnKZUtPjW%2BQ1xC7e7E6%2FzRY4cW6ZaQigCmZe7glOxfhYcogrqbZS4bUk9Hb2DBpSlGycPxcxVh1UJNMQuGKbkqTkdvwad8ZXcIY%2FPCHQKOYw06LmmVAKyaQklvTXrJzW6pYygBWvh5qRY1qxZ6JSwgfRq6BQS22viL%2BCPUBr6dzlmqkjZHVTIv%2Ft7sjqlZRvJBuDTbpp04dOqN48Tt%2BB2B8pn8GkMiLHUbBM7erLZUOo9xvYuhXDLFPCii2yh%2FJJ094dM%2F6SjTS8qy8YJQN6p%2BaeL4W%2FlW4Krfp0y7RDO7QVtYClGIs2iAlKwzh373U05b%2B02p2GN4Ph4Lt6eKF%2BtkuXZogwM1WhcFtgFfHuYHDuLDlb6cf16hy3qnAmSIlaQD1DCgf1yujbQ4jC6aoVzIc%2B2slzjXDprA2OF7XQgoSe0mJV2AAesMB%2B0LlQIwrZbV0AY6mAEloZfmx30f4OVq9ZllgDWX8jzRcuvmh9HYxBEc8h%2BY6OKOYr%2BmnsoFvXkcvv%2BTt%2FEfu5ERIF4o9PpDHQ1iDbSipEr1ukfn11QyxZZ8bWTq0lHF%2FvKF6M2G7FUm78e40xX%2FAIsQkR7kv%2FnlWU1nqX3b6vxLSjYLqy%2F8AMXmXBG1g98VpHMrtpuDVIu%2BQHEJLDZ66Iq25Q4hMg%3D%3D&amp;Expires=1779782614\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">Once a victim clicks a link and enters their credentials, the data appears instantly on the attacker\u2019s live administration panel. <\/p>\n<p class=\"wp-block-paragraph\">The attacker then triggers an OTP request on their own device at the same moment the victim is prompted for one. The victim types in the code, and the attacker captures it in seconds, bypassing multifactor authentication entirely.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/a5d6e8cf-ead9-403e-b9c3-65529f0d00e0\/Phishing-Services-Use-RCS-and-iMessage-to-Bypass-Traditional-SMS-Security-Filters.pdf?AWSAccessKeyId=ASIA2F3EMEYEX6LT542O&amp;Signature=Jlcmln3UyY5DsaIpiCPPefTc4QY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjELD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBtI89LgxZ6uqNh6T%2BpNqgER0Kcq9WLqoJ0UH38LEBdMAiEAionb9CbnbEq7pWmSlmRu90mkBZuNLUP0rFv7UAzK15Iq8wQIeRABGgw2OTk3NTMzMDk3MDUiDIRiSxNkhsX6fsWuWCrQBKZExNsIgj%2F3PVzaUKL6gtZlmDUESf%2FY%2F3g%2BjN0jcBAzniqh8VSEqhee0iUtSxAvRp4tByxD4McWPlrGE3hLKHAlkpjaT%2BDbKSTckjZZW6%2FSOPMHWAwcopLxmYrLwRKOOMA7UyeKxln9W1Ml8dIUWbAJrsU9vPpz98%2BCdwwudpntoL4hp6ewNSFzisvZp6zMVrbRGlizv3xkd5IWxrWmIZGdaUyzpDiVl57dW%2F5AtSF5D2mBBQljRLCMh9mfsxhzjmBIw%2FceHQRpvdYaVAtt80g%2BYOMYbQdQfAIQySWnjdIVF%2B54pUfIebzrRhfnjEua%2BkcVbU3t6cXdOOOTDzDxcbkr35gnKZUtPjW%2BQ1xC7e7E6%2FzRY4cW6ZaQigCmZe7glOxfhYcogrqbZS4bUk9Hb2DBpSlGycPxcxVh1UJNMQuGKbkqTkdvwad8ZXcIY%2FPCHQKOYw06LmmVAKyaQklvTXrJzW6pYygBWvh5qRY1qxZ6JSwgfRq6BQS22viL%2BCPUBr6dzlmqkjZHVTIv%2Ft7sjqlZRvJBuDTbpp04dOqN48Tt%2BB2B8pn8GkMiLHUbBM7erLZUOo9xvYuhXDLFPCii2yh%2FJJ094dM%2F6SjTS8qy8YJQN6p%2BaeL4W%2FlW4Krfp0y7RDO7QVtYClGIs2iAlKwzh373U05b%2B02p2GN4Ph4Lt6eKF%2BtkuXZogwM1WhcFtgFfHuYHDuLDlb6cf16hy3qnAmSIlaQD1DCgf1yujbQ4jC6aoVzIc%2B2slzjXDprA2OF7XQgoSe0mJV2AAesMB%2B0LlQIwrZbV0AY6mAEloZfmx30f4OVq9ZllgDWX8jzRcuvmh9HYxBEc8h%2BY6OKOYr%2BmnsoFvXkcvv%2BTt%2FEfu5ERIF4o9PpDHQ1iDbSipEr1ukfn11QyxZZ8bWTq0lHF%2FvKF6M2G7FUm78e40xX%2FAIsQkR7kv%2FnlWU1nqX3b6vxLSjYLqy%2F8AMXmXBG1g98VpHMrtpuDVIu%2BQHEJLDZ66Iq25Q4hMg%3D%3D&amp;Expires=1779782614\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-from-stolen-credentials-to-tokenized-financial-control\" class=\"wp-block-heading\"><strong>From Stolen Credentials to Tokenized Financial Control<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">What separates this generation of phishing operations from older ones is what happens after credentials are stolen. <a href=\"https:\/\/cybersecuritynews.com\/crypto-casinos-cybersecurity-protecting-your-wallet\/\" id=\"137197\" target=\"_blank\" rel=\"noreferrer noopener\">These platforms focus heavily on digital wallet<\/a> provisioning, a process that lets attackers load a victim\u2019s payment card onto an attacker-controlled device. <\/p>\n<p class=\"wp-block-paragraph\">Once the card is tokenized inside a digital wallet, it can be used for high-value purchases, tap-to-pay transactions, and cash withdrawals without ever needing the physical card.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/a5d6e8cf-ead9-403e-b9c3-65529f0d00e0\/Phishing-Services-Use-RCS-and-iMessage-to-Bypass-Traditional-SMS-Security-Filters.pdf?AWSAccessKeyId=ASIA2F3EMEYEX6LT542O&amp;Signature=Jlcmln3UyY5DsaIpiCPPefTc4QY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjELD%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBtI89LgxZ6uqNh6T%2BpNqgER0Kcq9WLqoJ0UH38LEBdMAiEAionb9CbnbEq7pWmSlmRu90mkBZuNLUP0rFv7UAzK15Iq8wQIeRABGgw2OTk3NTMzMDk3MDUiDIRiSxNkhsX6fsWuWCrQBKZExNsIgj%2F3PVzaUKL6gtZlmDUESf%2FY%2F3g%2BjN0jcBAzniqh8VSEqhee0iUtSxAvRp4tByxD4McWPlrGE3hLKHAlkpjaT%2BDbKSTckjZZW6%2FSOPMHWAwcopLxmYrLwRKOOMA7UyeKxln9W1Ml8dIUWbAJrsU9vPpz98%2BCdwwudpntoL4hp6ewNSFzisvZp6zMVrbRGlizv3xkd5IWxrWmIZGdaUyzpDiVl57dW%2F5AtSF5D2mBBQljRLCMh9mfsxhzjmBIw%2FceHQRpvdYaVAtt80g%2BYOMYbQdQfAIQySWnjdIVF%2B54pUfIebzrRhfnjEua%2BkcVbU3t6cXdOOOTDzDxcbkr35gnKZUtPjW%2BQ1xC7e7E6%2FzRY4cW6ZaQigCmZe7glOxfhYcogrqbZS4bUk9Hb2DBpSlGycPxcxVh1UJNMQuGKbkqTkdvwad8ZXcIY%2FPCHQKOYw06LmmVAKyaQklvTXrJzW6pYygBWvh5qRY1qxZ6JSwgfRq6BQS22viL%2BCPUBr6dzlmqkjZHVTIv%2Ft7sjqlZRvJBuDTbpp04dOqN48Tt%2BB2B8pn8GkMiLHUbBM7erLZUOo9xvYuhXDLFPCii2yh%2FJJ094dM%2F6SjTS8qy8YJQN6p%2BaeL4W%2FlW4Krfp0y7RDO7QVtYClGIs2iAlKwzh373U05b%2B02p2GN4Ph4Lt6eKF%2BtkuXZogwM1WhcFtgFfHuYHDuLDlb6cf16hy3qnAmSIlaQD1DCgf1yujbQ4jC6aoVzIc%2B2slzjXDprA2OF7XQgoSe0mJV2AAesMB%2B0LlQIwrZbV0AY6mAEloZfmx30f4OVq9ZllgDWX8jzRcuvmh9HYxBEc8h%2BY6OKOYr%2BmnsoFvXkcvv%2BTt%2FEfu5ERIF4o9PpDHQ1iDbSipEr1ukfn11QyxZZ8bWTq0lHF%2FvKF6M2G7FUm78e40xX%2FAIsQkR7kv%2FnlWU1nqX3b6vxLSjYLqy%2F8AMXmXBG1g98VpHMrtpuDVIu%2BQHEJLDZ66Iq25Q4hMg%3D%3D&amp;Expires=1779782614\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">One prominent example highlighted in the research is a platform called YY Lai Yu, which has been active since August 2024 and offers over 400 phishing templates targeting users across 119 countries. <\/p>\n<p class=\"wp-block-paragraph\">Defenders are advised to adopt FIDO2\/WebAuthn authentication as a countermeasure against real-time OTP interception. <\/p>\n<p class=\"wp-block-paragraph\">Banks should also pair stronger authentication with risk-based verification and device fingerprinting during the digital wallet provisioning process to make stolen credentials much harder to weaponize.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong> <strong><strong><a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a><\/strong><\/strong>.<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n<p class=\"wp-block-paragraph\">\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/phishing-services-use-rcs-and-imessage\/\">Phishing Services Use RCS and iMessage to Bypass Traditional SMS Security Filters<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/phishing-services-use-rcs-and-imessage\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing Services Use RCS and iMessage to Bypass Traditional SMS Security Filters A new wave of phishing operations is quietly changing the way cybercriminals steal financial data from everyday people. Rather than relying on traditional SMS messages that carriers can easily flag and block, threat actors are now using encrypted messaging channels like Rich Communication [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-13152","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13152"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13152"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13152\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}