Google has initiated legal proceedings against a Chinese software developer involved in online fraud schemes. This software has allegedly led to the theft of over $1 billion from more than a million victims across 121 countries, according to the Financial Times.
The lawsuit targets a Chinese hacker group that developed the Lighthouse platform. By offering a subscription, they provide cybercriminals access to phishing tools that enable large-scale fraudulent campaigns. These services allow the creation of fake emails, SMS messages, and fraudulent websites, including replicas of Google and YouTube, to extract sensitive user information.
Google aims to win the lawsuit by leveraging U.S. racketeering and computer fraud laws. This would enable the company to collaborate with mobile operators and hosting providers to block domains and servers supporting the Lighthouse platform.
"Criminals exploit the trust and reputation of our brand to lure users into dangerous phishing attacks. Engaging our engineers and legal teams to fight for these users is imperative," said Google’s Chief Legal Officer Halima DeLine Prado.
Lighthouse Enterprise promotes its services through online forums and channels on YouTube and Telegram. The hacker group also recruits and trains new members, utilizing their skills to enhance their software. Criminals who approach the company can choose from hundreds of templates for fake websites, paying in cryptocurrency.
In addition to tools, offenders can obtain a list of potential victims from a "data group" to send millions of fraudulent SMS messages with links to fake sites that require users to input personal and financial information. Stolen data is used to gain access to bank accounts, email accounts, or digital wallets, or is resold on the dark web.
Google cites data from cybersecurity firm Silent Push, indicating that the Chinese group Smishing Triad used the Lighthouse program to create 200,000 counterfeit websites. These sites garnered around 50,000 visits daily, putting millions of U.S. bank cards at risk.