logo

Scams, Slaves and (Malware-as-a) Service: Tracking a Trojan to Cambodia’s Scam Centers

ID: 9e7698b1-88c0-5db8-a095-c0a02e249d42

STIX ID: report--9e7698b1-88c0-5db8-a095-c0a02e249d42

Feed Name: Infoblox Blog

Threat Score
78/100

Date Published: 2026-04-10

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

Infoblox Threat Intel and Chong Lua Dao detail an active, evolving Android banking trojan-as-a-service used by multilingual scam centers (including K99 Triumph City in Sihanoukville, Cambodia) to distribute malicious APKs via crafted lure domains impersonating government and financial services; the malware provides real-time remote monitoring, SMS/OTP interception, credential and biometric exfiltration, and is supported by hundreds of rotating domains and C2 servers, with technical IOCs and victim testimony linking the infrastructure to organized forced-labor scam operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.