Researchers have discovered a new phishing kit, Xiū gǒu, that has been used in campaigns targeting Australia, Japan, Spain, the United Kingdom, and the United States. The attacks have been taking place since at least September 2024.

Netcraft said it has identified more than 2,000 phishing websites associated with the kit, and the attacks target various industries, including public sectors, postal, digital and banking services.
“Threat actors using the kit to deploy phishing websites often rely on Cloudflare’s anti-bot and hosting obfuscation capabilities to prevent detection,” Netcraft said in its report.
See also: Phish n' Ships: Phishing campaign infects legitimate online stores
Some aspects of the phishing kit were documented by security researchers Will Thomas (@BushidoToken) and Fox_threatintel (@banthisguy9349) in September 2024.
Phishing kits, such as Xiū gǒu, allow hackers with less knowledge and skills to carry out effective attacksthat could lead to the theft of sensitive information. Xiū gǒu, which was developed by a Chinese-speaking threat actor, provides users with an administration panel and is developed using Golang and Vue.js. The phishing kit is also designed to steal credentials and other information from fake phishing pages hosted on the “.top” top-level domain, via Telegram.
The attacks are spread via Rich Communications Services (RCS) messages rather than SMS, warning recipients of alleged parking fines and failed package deliveries. There is also a link that they are asked to open (which, however, has been used by a URL shortener service). Users must open the link to pay the fine or update their package delivery address.
See also: Fraudsters exploit Eventbrite services for phishing attacks
“Scams typically manipulate victims into providing their personal information and making payments,” Netcraft said.
RCS, which is primarily available through Apple Messages and Google Messages, offers users an upgraded messaging experience.
Protection
Users should be wary of messages they receive from strangers or from supposedly well-known companies. Many times, phishing attacks start with a simple message asking for the user's login details.

Next, they should regularly update their software, including the operating system and applications. These updates often include security that can protect the user from the latest threats.
See also: Phishing: Midnight Blizzard hackers target users with RDP files
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Using reliable security software, such as an antivirus or security app, can help protect against attacks. These tools can identify and block suspicious websites or messages that are trying to steal user information.
Finally, users should be careful when downloading applications from the internet. Many times, applications that seem innocent may contain hidden code that can steal user information or cause other security threats.
Source: thehackernews.com
