Inside the Global “MaaS” Engine of the K99 Scam Compound
ID: b413d394-493c-59db-80bd-fd99aba3516a
STIX ID: report--b413d394-493c-59db-80bd-fd99aba3516a
Feed Name: securityonline.info
Infoblox Threat Intel and partner NGO Chong Lua Dao exposed an industrial-scale Android banking trojan MaaS linked to the K99 Triumph City scam compound in Sihanoukville, Cambodia. The operation uses multilingual social-engineering lures and fake government sites to install malicious APKs that escalate permissions, capture biometrics via spoofed KYC overlays, exfiltrate credentials and data, and enable real-time surveillance and financial fraud across at least 21 countries; infrastructure is resilient and rapidly rotated through dozens of domains monthly, and the campaign is supported by forced labor at the compound.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
