The cybersecurity landscape is facing a growing threat from sophisticated Phishing-as-a-Service (PhaaS) that are democratizing cybercrime by lowering the technical barriers for fraudsters worldwide. Lucid PhaaS is one such example.
See also: RaccoonO365: Microsoft & Cloudflare dismantle phishing network

Amidst these emerging threats, the Lucid PhaaS has established itself as a powerful force in the underground economy, enabling massive phishing across multiple continents and industry sectors.
Security researchers have uncovered an extensive criminal infrastructure centered around Lucid PhaaS, which has successfully deployed over 17,500 phishing domains targeting 316 prominent brands across 74 countries. This scale represents one of the largest documented PhaaS operations to date, demonstrating the platform’s sophisticated capabilities and its widespread adoption by cybercriminals.
The business spans diverse sectors, including financial institutions, government agencies, postal services, and toll companies, demonstrating the platform's flexibility in mimicking various organizational structures and brand identities.
The campaign's geographic reach extends from major financial centers in North America and Europe to emerging markets in Asia, Africa and Latin America, suggesting a coordinated global operation rather than isolated regional operations.
Netcraft analysts identified the malware through advanced fingerprinting and correlation analysis techniques that linked Lucid to its companion platform, Lighthouse PhaaS , through shared anti-tracking infrastructure and identical pattern systems.
See also: VoidProxy: New phishing service steals credentials

The investigation revealed that Lucid operates through a subscription model where cybercriminals pay monthly fees for access to pre-configured phishing templates and hosting infrastructure. Each phishing template on the platform is assigned a unique identifier, such as the subject “kuda295” discovered during the analysis of a financial institution impersonation campaign. This nomenclature allows operators to efficiently manage multiple concurrent campaigns while maintaining operational security.
Lucid PhaaS uses advanced detection evasion techniques that represent a significant advancement in phishing technology. The platform implements a multi-layered filtering system that protects malicious content from security researchers and automated detection systems through several technical mechanisms.
The primary evasion technique requires visitors to access specific URL paths, such as “/servicios,” that are dynamically configured by the fraudsters and vary significantly between campaigns targeting the same brands. This path-based filtering makes automated detection difficult, as security systems cannot predict the required access patterns.
Additionally, the platform enforces geo-restrictions by requiring connections from specific proxy countries, effectively limiting exposure to security researchers operating from known analytics centers. User-Agent is another critical layer of evasion, with Lucid requiring mobile device signatures to display phishing content. This restriction aligns with the platform’s targeting strategy, as mobile users often exhibit reduced security awareness and operate on devices with limited security tools.
See also: Lucid phishing platform targets iOS and Android users

When visitors do not meet these criteria, Lucid displays convincing fake e-commerce storefronts featuring products such as shoes or women’s clothing, complete with professional layouts and product catalogs. These anti-tracking pages serve a dual purpose by maintaining the illusion of legitimate commerce while hiding the underlying criminal infrastructure.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
