logo

Evolving Mule Tactics in the META Region Banking Sector

ID: ee7555c5-4755-5d47-9d3c-6d29220610b0

STIX ID: report--ee7555c5-4755-5d47-9d3c-6d29220610b0

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2025-08-20

Date Updated: 2026-04-28

...
...

This report analyzes an evolving, multi-stage mule-fraud campaign against retail banks in the META region, documenting stages from simple IP masking to advanced techniques such as roaming eSIMs, Starlink obfuscation, GPS spoofing, SIM removal, credential handoffs, and physical shipment of preconfigured devices; it also provides detection indicators (GPS/IP/SIM mismatches, behavioral biometric shifts, device reuse) and a set of pragmatic, layered defenses including device telemetry fusion, ML-based behavioral biometrics, enhanced KYC, and threat intelligence sharing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.