logo

Scams, Slaves and (Malware-as-a) Service: Tracking a Trojan to Cambodia’s Scam Centers

ID: 5f265ac6-d614-5b0f-a09f-514c7e49d842

STIX ID: report--5f265ac6-d614-5b0f-a09f-514c7e49d842

Feed Name: Infoblox Threat Intel Blog

Threat Score
80/100

Date Published: 2026-04-10

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

Infoblox Threat Intel and partner Chong Lua Dao describe an active Android banking trojan MaaS used to distribute malicious APKs via lookalike government and banking lure sites, enabling real-time surveillance, SMS/OTP interception, biometric capture, and financial fraud; the operation is large-scale, multilingual, links to scam centers (including K99 Triumph City), registers ~35 domains/month, and includes identified domains, C2 IPs, and malware hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.