15 November 2023

Police shut down BulletProftLink PaaS operation


Police shut down BulletProftLink PaaS operation

Malaysian police in cooperation with the Australian Federal Police (AFP) and the US Federal Bureau of Investigation (FBI) dismantled a major phishing-as-a-service (PhaaS) operation called BulletProftLink (aka BulletProofLink and Anthrax).

Believed to be in operation since at least 2015, the platform provided a wide range of services at a relatively low cost, including more than 300 phishing templates mimicking known brands and services such as American Express, Bank of America, DHL, Microsoft, and Naver, phishing kits, email templates, hosting, and automated services. BulletProftLink is said to have amassed at least 8,000 customers.

The Malaysian authorities arrested 8 people aged between 29 and 56 across the country, including an alleged mastermind behind the operation. Alongside the arrests, the police confiscated servers, computers, jewelry, vehicles, and cryptocurrency wallets containing approximately 965,808 Malaysian ringgit (~$213,000).

On Tuesday, the US Department of Justice announced the takedown of the IPStorm malware botnet infrastructure, along with the guilty plea of the service’s operator Sergei Makinin.

Back to the list

Latest Posts

Cyber Security Week in Review: October 4, 2024

Cyber Security Week in Review: October 4, 2024

In brief: the US disrupts FSB-linked ColdRiver hackers’ operations, Lockbit and EvilCorp members arrested, and more.
4 October 2024
Critical Ivanti EPM RCE flaw exploited in the wild

Critical Ivanti EPM RCE flaw exploited in the wild

The flaw is an SQL Injection issue that allows a remote attacker to execute arbitrary SQL queries in database.
3 October 2024
New China-aligned threat actor CeranaKeeper steals data from Southeast Asian entities

New China-aligned threat actor CeranaKeeper steals data from Southeast Asian entities

CeranaKeeper is notable for its evolving backdoor techniques, which allow it to evade detection and facilitate extensive data theft.
3 October 2024