15 November 2023

Police shut down BulletProftLink PaaS operation


Police shut down BulletProftLink PaaS operation

Malaysian police in cooperation with the Australian Federal Police (AFP) and the US Federal Bureau of Investigation (FBI) dismantled a major phishing-as-a-service (PhaaS) operation called BulletProftLink (aka BulletProofLink and Anthrax).

Believed to be in operation since at least 2015, the platform provided a wide range of services at a relatively low cost, including more than 300 phishing templates mimicking known brands and services such as American Express, Bank of America, DHL, Microsoft, and Naver, phishing kits, email templates, hosting, and automated services. BulletProftLink is said to have amassed at least 8,000 customers.

The Malaysian authorities arrested 8 people aged between 29 and 56 across the country, including an alleged mastermind behind the operation. Alongside the arrests, the police confiscated servers, computers, jewelry, vehicles, and cryptocurrency wallets containing approximately 965,808 Malaysian ringgit (~$213,000).

On Tuesday, the US Department of Justice announced the takedown of the IPStorm malware botnet infrastructure, along with the guilty plea of the service’s operator Sergei Makinin.

Back to the list

Latest Posts

What is Vulnerability Management? A Beginner's Guide

What is Vulnerability Management? A Beginner's Guide

In this article will try to cover basics of vulnerability management process and why it is important to every company.
11 September 2024
Cyber Security Week in Review: September 6, 2024

Cyber Security Week in Review: September 6, 2024

In brief: the US charges Russian GRU hackers for attacks on Ukraine, Apache, Cisco, Zyxel patch high-risk flaws, Google fixes Android zero-day, and more.
6 September 2024
Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Some of the documents appeared to be part of legitimate Red Team exercises, while other were intended for malicious purposes.
5 September 2024