Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • Uncategorized
  • Krebs On Security
  • FBI, Dutch Police Disrupt ‘Manipulaters’ Phishing Gang
  • Krebs On Security

FBI, Dutch Police Disrupt ‘Manipulaters’ Phishing Gang

BrianKrebs January 31, 2025
0

The FBI and authorities in The Netherlands this week seized dozens of servers and domains for a hugely popular spam and malware dissemination service operating out of Pakistan. The proprietors of the service, who use the collective nickname “The Manipulaters,” have been the subject of three stories published here since 2015. The FBI said the main clientele are organized crime groups that try to trick victim companies into making payments to a third party.

One of several current Fudtools sites run by the principals of The Manipulators.

On January 29, the FBI and the Dutch national police seized the technical infrastructure for a cybercrime service marketed under the brands Heartsender, Fudpage and Fudtools (and many other “fud” variations). The “fud” bit stands for “Fully Un-Detectable,” and it refers to cybercrime resources that will evade detection by security tools like antivirus software or anti-spam appliances.

The Dutch authorities said 39 servers and domains abroad were seized, and that the servers contained millions of records from victims worldwide — including at least 100,000 records pertaining to Dutch citizens.

A statement from the U.S. Department of Justice refers to the cybercrime group as Saim Raza, after a pseudonym The Manipulaters communally used to promote their spam, malware and phishing services on social media.

“The Saim Raza-run websites operated as marketplaces that advertised and facilitated the sale of tools such as phishing kits, scam pages and email extractors often used to build and maintain fraud operations,” the DOJ explained.

The core Manipulaters product is Heartsender, a spam delivery service whose homepage openly advertised phishing kits targeting users of various Internet companies, including Microsoft 365, Yahoo, AOL, Intuit, iCloud and ID.me, to name a few.

The government says transnational organized crime groups that purchased these services primarily used them to run business email compromise (BEC) schemes, wherein the cybercrime actors tricked victim companies into making payments to a third party.

“Those payments would instead be redirected to a financial account the perpetrators controlled, resulting in significant losses to victims,” the DOJ wrote. “These tools were also used to acquire victim user credentials and utilize those credentials to further these fraudulent schemes. The seizure of these domains is intended to disrupt the ongoing activity of these groups and stop the proliferation of these tools within the cybercriminal community.”

Manipulaters advertisement for “Office 365 Private Page with Antibot” phishing kit sold via Heartsender. “Antibot” refers to functionality that attempts to evade automated detection techniques, keeping a phish deployed and accessible as long as possible. Image: DomainTools.

KrebsOnSecurity first wrote about The Manipulaters in May 2015, mainly because their ads at the time were blanketing a number of popular cybercrime forums, and because they were fairly open and brazen about what they were doing — even who they were in real life.

We caught up with The Manipulaters again in 2021, with a story that found the core employees had started a web coding company in Lahore called WeCodeSolutions — presumably as a way to account for their considerable Heartsender income. That piece examined how WeCodeSolutions employees had all doxed themselves on Facebook by posting pictures from company parties each year featuring a large cake with the words FudCo written in icing.

A follow-up story last year about The Manipulaters prompted messages from various WeCodeSolutions employees who pleaded with this publication to remove stories about them. The Saim Raza identity told KrebsOnSecurity they were recently released from jail after being arrested and charged by local police, although they declined to elaborate on the charges.

The Manipulaters never seemed to care much about protecting their own identities, so it’s not surprising that they were unable or unwilling to protect their own customers. In an analysis released last year, DomainTools.com found the web-hosted version of Heartsender leaked an extraordinary amount of user information to unauthenticated users, including customer credentials and email records from Heartsender employees.

Almost every year since their founding, The Manipulaters have posted a picture of a FudCo cake from a company party celebrating its anniversary.

DomainTools also uncovered evidence that the computers used by The Manipulaters were all infected with the same password-stealing malware, and that vast numbers of credentials were stolen from the group and sold online.

“Ironically, the Manipulaters may create more short-term risk to their own customers than law enforcement,” DomainTools wrote. “The data table ‘User Feedbacks’ (sic) exposes what appear to be customer authentication tokens, user identifiers, and even a customer support request that exposes root-level SMTP credentials–all visible by an unauthenticated user on a Manipulaters-controlled domain.”

Police in The Netherlands said the investigation into the owners and customers of the service is ongoing.

“The Cybercrime Team is on the trail of a number of buyers of the tools,” the Dutch national police said. “Presumably, these buyers also include Dutch nationals. The investigation into the makers and buyers of this phishing software has not yet been completed with the seizure of the servers and domains.”

U.S. authorities this week also joined law enforcement in Australia, France, Greece, Italy, Romania and Spain in seizing a number of domains for several long-running cybercrime forums and services, including Cracked and Nulled. According to a statement from the European police agency Europol, the two communities attracted more than 10 million users in total.

Other domains seized as part of “Operation Talent” included Sellix, an e-commerce platform that was frequently used by cybercrime forum members to buy and sell illicit goods and services.

About The Author

BrianKrebs

See author's posts

Original post here

Continue Reading

Previous: Infrastructure Laundering: Blending in with the Cloud
Next: Who’s Behind the Seized Forums ‘Cracked’ & ‘Nulled’?

Trending Now

Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics vpn.jpg 1

Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics

May 21, 2025
PureRAT Malware Spikes 4x in 2025, Deploying PureLogs to Target Russian Firms dll.jpg 2

PureRAT Malware Spikes 4x in 2025, Deploying PureLogs to Target Russian Firms

May 21, 2025
Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims ai.jpg 3

Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims

May 21, 2025
Securing CI/CD workflows with Wazuh Wazuh.jpg 4

Securing CI/CD workflows with Wazuh

May 21, 2025
How to Detect Phishing Attacks Faster: Tycoon2FA Example anyrun.jpg 5

How to Detect Phishing Attacks Faster: Tycoon2FA Example

May 21, 2025
Researchers Expose PWA JavaScript Attack That Redirects Users to Adult Scam Apps js-malware.jpg 6

Researchers Expose PWA JavaScript Attack That Redirects Users to Adult Scam Apps

May 21, 2025

Related Stories

ddosbomb.png
  • Krebs On Security

KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS

BrianKrebs May 20, 2025 0
breached-nonstop.png
  • Krebs On Security

Breachforums Boss to Pay $700k in Healthcare Breach

BrianKrebs May 15, 2025 0
winupdatedate.png
  • Krebs On Security

Patch Tuesday, May 2025 Edition

BrianKrebs May 14, 2025 0
eworldtrade.png
  • Krebs On Security

Pakistani Firm Shipped Fentanyl Analogs, Scams to US

BrianKrebs May 7, 2025 0
x-ai.png
  • Krebs On Security

xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs

BrianKrebs May 2, 2025 0
tylerb.png
  • Krebs On Security

Alleged ‘Scattered Spider’ Member Extradited to U.S.

BrianKrebs April 30, 2025 0

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics vpn.jpg 1
  • The Hacker News

Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics

May 21, 2025
PureRAT Malware Spikes 4x in 2025, Deploying PureLogs to Target Russian Firms dll.jpg 2
  • The Hacker News

PureRAT Malware Spikes 4x in 2025, Deploying PureLogs to Target Russian Firms

May 21, 2025
Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims ai.jpg 3
  • The Hacker News

Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims

May 21, 2025
Securing CI/CD workflows with Wazuh Wazuh.jpg 4
  • The Hacker News

Securing CI/CD workflows with Wazuh

May 21, 2025
How to Detect Phishing Attacks Faster: Tycoon2FA Example anyrun.jpg 5
  • The Hacker News

How to Detect Phishing Attacks Faster: Tycoon2FA Example

May 21, 2025
Researchers Expose PWA JavaScript Attack That Redirects Users to Adult Scam Apps js-malware.jpg 6
  • The Hacker News

Researchers Expose PWA JavaScript Attack That Redirects Users to Adult Scam Apps

May 21, 2025
Google Chrome Can Now Auto-Change Compromised Passwords Using Its Built-In Manager chrome.gif 7
  • The Hacker News

Google Chrome Can Now Auto-Change Compromised Passwords Using Its Built-In Manager

May 21, 2025

You may have missed

vpn.jpg
  • The Hacker News

Russian Hackers Exploit Email and VPN Vulnerabilities to Spy on Ukraine Aid Logistics

[email protected] The Hacker News May 21, 2025 0
dll.jpg
  • The Hacker News

PureRAT Malware Spikes 4x in 2025, Deploying PureLogs to Target Russian Firms

[email protected] The Hacker News May 21, 2025 0
ai.jpg
  • The Hacker News

Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims

[email protected] The Hacker News May 21, 2025 0
Wazuh.jpg
  • The Hacker News

Securing CI/CD workflows with Wazuh

[email protected] The Hacker News May 21, 2025 0
Copyright © 2025 All rights reserved. | MoreNews by AF themes.