logo

Inside the Global “MaaS” Engine of the K99 Scam Compound

ID: b413d394-493c-59db-80bd-fd99aba3516a

STIX ID: report--b413d394-493c-59db-80bd-fd99aba3516a

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Infoblox Threat Intel and partner NGO Chong Lua Dao exposed an industrial-scale Android banking trojan MaaS linked to the K99 Triumph City scam compound in Sihanoukville, Cambodia. The operation uses multilingual social-engineering lures and fake government sites to install malicious APKs that escalate permissions, capture biometrics via spoofed KYC overlays, exfiltrate credentials and data, and enable real-time surveillance and financial fraud across at least 21 countries; infrastructure is resilient and rapidly rotated through dozens of domains monthly, and the campaign is supported by forced labor at the compound.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.