logo

RUNLIR – phishing campaign targeting Netherlands

ID: 406612d0-adf4-53c5-a055-c8140d5114ca

STIX ID: report--406612d0-adf4-53c5-a055-c8140d5114ca

Feed Name: Group-IB Blog

Threat Score
72/100

Date Published: 2021-09-16

Date Updated: 2026-04-27

...
...

Group-IB researchers detail the RUNLIR phishing campaign (active since March 2021) that used smishing and spoofed Dutch organization websites to harvest banking credentials and personal data; the campaign relied on BlackTDS geo/anti-bot filtering, Yalishanda bulletproof hosting, and uAdmin phishing kits and employed an unusual “cut the card” social-engineering step to enable physical collection of cards and subsequent fraud, affecting hundreds of connected domains and posing a significant financial risk to victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.