Connect with us

Infosecurity

US and UK Join Forces to Dismantle Scam Centers Behind Billions in Fraud

Published

on

scam center takedowns

A New Alliance Against Cyber Fraud

The United States and the United Kingdom are pooling resources to shut down the sprawling scam centers that have siphoned billions from victims worldwide. A memorandum of understanding signed Thursday commits both nations to parallel investigations and shared intelligence on the organized crime networks behind these operations, many of which are based in Southeast Asia.

U.S. Attorney Jeanine Ferris Pirro met with senior officials from the U.K.’s National Crime Agency and Crown Prosecutor to formalize the agreement. Pirro stated the objective is to “disable” the Chinese gangs that operate these compounds.

How the Partnership Will Work

The memorandum outlines a framework for both countries to identify overlapping cases and decide which jurisdictions will bring charges. The goal is to prioritize cases that can deliver significant mutual impact.

Officials from both sides had already flagged substantial case overlaps. They are now committed to a joint disruption event with private industry partners, scheduled for early October in London and hosted by the National Crime Agency.

The Scam Center Strike Force Takes the Lead

This initiative is spearheaded by the Scam Center Strike Force, launched last November to coordinate U.S. enforcement against cyber-enabled fraud. The numbers are staggering: the FBI reports that cyber-enabled fraud accounts for nearly 85% of all losses reported to the agency. Americans lost over $12 billion to these scams last year — a figure likely far below reality, as many victims never come forward.

Assistant U.S. Attorney Karen Seifert leads the Strike Force. Testifying before Congress in March, she noted the team includes more than 150 personnel, drawing on prosecutors and agents from the FBI, IRS, and U.S. Postal Inspection Service.

Human Trafficking at the Core

These scam centers are not merely criminal enterprises; they are built on human trafficking. Victims are held in compounds across Myanmar, Cambodia, Laos, and neighboring countries, forced to run investment and romance fraud schemes. Chinese syndicates control the operations, often with the complicity of compromised local officials.

Early Wins and the Road Ahead

The Strike Force has already claimed a major victory. The disruption of Prince Group, a Chinese front company used to launder illicit proceeds, led to sanctions from both U.S. and U.K. agencies. The Justice Department also seized roughly $15 billion in bitcoin tied to the company’s CEO, Chen Zhi.

That seizure sent a clear message. But the problem is vast, and the syndicates are adaptive. The new US-UK partnership signals a recognition that no single nation can tackle this threat alone.

For more on related efforts, see how cyber fraud reporting works and the rise of Southeast Asian scam compounds.

Continue Reading

Infosecurity

Outsider Phishing Kit Survives Takedown: 700 New Pages Emerge

Published

on

Outsider phishing kit

A Takedown That Didn’t Stick

The Outsider phishing kit was supposed to be dead. In June, the FBI announced Operation Ghost Hook, a coordinated strike with Google and Lumen’s Black Lotus Labs that seized core admin servers, a Shopify storefront, roughly $100,000 from payment wallets, and thousands of domains. The message was clear: this phishing-as-a-service operation was finished.

It wasn’t.

New research from Group-IB, published on September 3, reveals the Outsider phishing kit has simply adapted. Within a month of the takedown, researchers identified more than 700 new phishing pages tied to the operation. The infrastructure took a hit, but the affiliates kept working.

Tracking the Outsider Phishing Kit’s Reach

Group-IB has been watching this threat actor, known as ChenLun, for a while. Between December 2025 and May 2026, the researchers logged over 100,000 phishing pages targeting at least 54 countries. Before Operation Ghost Hook, they had linked more than 10,000 unique domains to the kit.

The post-takedown surge of 700-plus new domains tells a troubling story. The affiliates who bought access to the Outsider phishing kit didn’t abandon ship when the FBI came knocking. They found new hosting, registered fresh domains, and kept running campaigns.

What the Kit Offers

The platform itself is remarkably polished. Group-IB found 267 ready-made phishing templates covering financial services, brokerage firms, telecom providers, postal services, government agencies, and toll systems. Campaigns spread through SMS, with the kit sold and managed through a Telegram ecosystem.

ChenLun has since deleted that Telegram channel. Before it vanished, the main group boasted over 5,000 subscribers and more than 230 paying customers.

AiTM Capabilities and Real-Time Data Theft

What makes the Outsider phishing kit particularly dangerous is its adversary-in-the-middle (AiTM) functionality. This isn’t a static clone page. Operators can interact with victims live during the phishing flow.

Think about what that means in practice. A victim lands on a fake portal. The operator can dynamically serve SMS, email, PIN, or app-based multifactor authentication challenges. They can redirect victims back to earlier pages to ask for additional payment details. The whole thing runs on WebSockets, providing live communication between the phishing page and an operator panel.

Group-IB identified JavaScript components that capture financial details, bank credentials, PayPal information, and authentication codes. The kit even tracks victims across browser sessions and detects security crawlers. Data entered by victims transmits in real time — including when someone abandons a form before hitting submit.

A Singapore Smishing Campaign Under the Microscope

To show how this plays out in the wild, researchers examined a smishing campaign impersonating Singapore’s Land Transport Authority (LTA). The messages created urgency around a supposed data synchronization issue. They even included instructions telling recipients how to disable their phone’s spam filtering.

The cloned portal collected vehicle registration numbers and phone numbers before redirecting victims to fraudulent payment screens. Those harvested numbers weren’t just for show. Group-IB said they were intended for intercepting SMS authentication codes at a later stage.

Spotting the Pages Before They Strike

There’s a silver lining for defenders. The phishing pages follow a consistent file-naming convention, with an alphabetical prefix marking the victim’s stage in the attack flow. Group-IB recommends organizations track new pages through those file-name signatures to trigger faster takedowns.

The company also advises continuous monitoring for SMS-linked brand abuse. For individuals, the guidance is straightforward: verify alerts through official apps rather than clicking links in messages.

This saga echoes other recent takedown attempts. The Tycoon2FA phishing service resumed activity post-takedown, showing that disrupting these operations requires ongoing effort, not just a single coordinated strike.

The Outsider phishing kit’s survival raises uncomfortable questions about how we combat cybercrime. When the infrastructure falls, the affiliates scatter — and often, they simply rebuild elsewhere.

Continue Reading

Infosecurity

Serbian Student Activist’s iPhone Hacked via Pegasus Zero-Click Exploit

Published

on

Pegasus zero-click exploit

Serbian Activist Targeted in Silent iPhone Hack

An activist tied to Serbia’s student protest movement had their iPhone silently compromised by NSO Group’s Pegasus spyware. The attack used an iMessage zero-click exploit, according to a forensic report from the Citizen Lab and the SHARE Foundation.

The researchers found high-confidence signs of infection on the device spanning December 2025 and January 2026. They caution that this doesn’t rule out earlier or later breaches. The victim agreed to go public but chose to stay anonymous. The exact infection date was withheld to shield their privacy.

This isn’t an isolated incident. It’s part of a broader pattern of surveillance targeting Serbia’s pro-democracy voices.

How the Pegasus Zero-Click Exploit Worked

The September 2 research detailed an iMessage zero-click exploit. The Citizen Lab believes Apple patched this vulnerability in iOS 18.4.1, released in April 2025. Yet the damage was already done.

Zero-click means the target does nothing. No link to tap. No attachment to open. The spyware simply arrives and takes hold.

The infection would have been invisible to the owner. Once inside, Pegasus grants total access. Notes, photos, even encrypted messages become readable. The attacker can silently switch on the microphone and camera. That level of access is chilling for anyone, but especially for someone involved in political activism.

What the Victim Experienced

The investigation started after the activist received an Apple Threat Notification. That alert flags potential targeting by mercenary spyware.

It was one of at least 14 such notifications documented by the SHARE Foundation. The recipients included student movement members, civil society figures, and an opposition member of parliament. The Citizen Lab noted the timing — ahead of key 2026 election cycles.

Serbia’s Long History of Spyware Abuse

This case doesn’t exist in a vacuum. The Toronto-based lab points to a longer record of surveillance abuses in Serbia.

There have been previous Pegasus infections of civil society. More recently, forensic tools from Cellebrite were allegedly used to plant NoviSpy spyware. On the same day as this report, the SHARE Foundation and Amnesty Tech confirmed finding a new NoviSpy variant on another student activist’s device.

The pattern is clear. The Serbian government has repeatedly denied involvement, but the evidence keeps mounting. For a deeper look at how these tools are used, see our analysis of commercial spyware proliferation.

Got an Apple Threat Notification? Here’s What to Do

The Citizen Lab’s advice is blunt: treat the notification as presuming infection. Don’t wait. Seek expert help immediately.

Their recommendations go beyond the individual. Close contacts — family, collaborators — should also get screened. People at heightened risk should enable Apple’s Lockdown Mode. And everyone should keep devices updated.

If you’re in Serbia, the SHARE Foundation is the first port of call. Elsewhere, trusted experts like Access Now’s Digital Security Helpline can help. The lab acknowledges there’s no substitute for personalized advice, but points to resources like Security Planner for initial guidance.

What Lockdown Mode Actually Does

Lockdown Mode is Apple’s hardened security state. It restricts certain functions to block common spyware vectors. It’s not perfect, but it raises the bar significantly.

For activists, journalists, and anyone else in the crosshairs, it’s a sensible precaution. Combine it with regular updates and you reduce your attack surface considerably.

Continued Targeting of Serbia’s Pro-Democracy Movement

The Citizen Lab’s forensic work on other notification cases is ongoing. This confirmation demonstrates that Serbia’s pro-democracy movement remains in the crosshairs.

The timing is no accident. With elections approaching, silencing dissent becomes a priority for those in power. The use of zero-click exploits makes that silencing easier — and harder to detect.

For those concerned about their own devices, understanding how spyware infects iPhones is the first line of defense. The second is knowing what to do when you get that alert.

This case is a reminder that digital security isn’t just about strong passwords. It’s about recognizing that some attackers don’t need you to make a mistake. They just need your phone number.

Continue Reading

Infosecurity

Spyware campaign targets Serbian opposition figures, activists and student protesters

Published

on

Serbian opposition spyware

Spyware hits a broad swath of Serbian civil society

At least 14 Serbians have been caught in a spyware dragnet since December, with victims ranging from a sitting member of Parliament to student protesters who helped organize election efforts. Digital forensic researchers say the campaign appears timed to political events — local elections in March and a likely parliamentary vote this fall.

The SHARE Foundation, a Serbian digital rights group, launched its investigation after a dozen people came forward in August saying Apple had alerted them to possible state-sponsored hacking. In some cases, the alerts were justified: researchers found actual infections.

Two distinct types of spyware were identified on victims’ phones, according to the foundation’s report.

Pegasus and NoviSpy both found on victims’ devices

Experts at the Citizen Lab at the University of Toronto confirmed that one student protester’s phone was infected with zero-click Pegasus spyware between December 2025 and January 2026. Zero-click means no interaction from the victim was needed — no rogue link tapped, no malicious attachment opened.

Amnesty International, which peer-reviewed the SHARE Foundation’s findings, verified that a newer Android spyware called NoviSpy was used in at least two cases. Researchers are still examining 11 more phones whose owners received Apple threat notifications.

Donncha Ó Cearbhaill, who heads Amnesty’s Security Lab, told Recorded Future News the new NoviSpy variant “appears to have been updated to avoid detection.”

A chilling detail: texts read live on TV

One confirmed NoviSpy victim had text messages read aloud on a Serbian television network known to be friendly with the ruling party, the SHARE Foundation said. That detail underscores how surveillance can feed directly into propaganda.

Pattern of repression, or “trivial sensationalism”?

Ó Cearbhaill framed the spyware as one piece of a larger puzzle. “Combined with the excessive use of force against protesters, arbitrary arrests and unfounded criminal and misdemeanor charges, as well as vicious smear campaigns targeting individuals involved or perceived to support the anti-government protests, digital surveillance is yet another element of a broader pattern of systemic repression of critical voices,” he said.

Serbian authorities deny the allegations. The country’s intelligence agency, the BIA, dismissed the findings as “nothing more than trivial sensationalism,” adding that the accusations “clearly indicate the true intentions of the individuals and organisations making them, namely, acting in the interests of certain foreign intelligence services and pressure groups.”

Notably, the spyware activity tracked with the March local elections, which student protesters were deeply involved in. They were pushing to oust the ruling party, which critics describe as increasingly authoritarian.

Serbia has form when it comes to phone hacking

This isn’t a first for Serbia. The country has previously been caught targeting protesters, journalists and dissidents with both Pegasus and NoviSpy.

  • In March 2025, Amnesty said its forensic researchers found two investigative journalists in Serbia had been targeted with Pegasus.
  • A month earlier, Amnesty reported that Cellebrite — whose phone-breaking software lets governments extract data from devices — cut ties with Serbia after an Amnesty report documented NoviSpy being used against dissidents and journalists whose phones were taken while in government custody.

Police never asked detainees for their passwords in those cases, Amnesty said. Instead, they used Cellebrite to break in, then implanted the spyware.

The key difference between the two spyware types: NoviSpy requires physical access to the phone, while Pegasus can slip in remotely with zero interaction. That’s why many NoviSpy infections in Serbia have been discovered only after victims were detained and their phones confiscated during questioning.

NSO Group’s decade of promises, same abuses

John Scott-Railton, a Citizen Lab researcher involved in the Pegasus confirmation, pointed to a grim continuity. “Ten years ago, we found Pegasus spyware’s first target, pro-democracy campaigner Ahmed Mansour and he’s still jailed today,” he said. “Today, it’s Serbian students campaigning for democracy.”

“NSO has spent a decade promising reform, lobbying and shuffling ownership structures, and yet the product and the abuses haven’t changed,” Scott-Railton added. The NSO Group did not respond to a request for comment.

Both Pegasus and NoviSpy give operators extraordinary access — photos, contacts, messages, files, and even the ability to switch on microphones to hear conversations happening near the phone, not just on it.

“They are ready to use whatever it takes”

Ognjen Rašić, a third-year student and protester whose phone is still under forensic study, believes he was likely hit with Pegasus. He’s never been in police custody, which a NoviSpy attack would likely require.

Rašić has protested peacefully against the government for years and joined a student election-preparation team about a year ago. The potential infection unsettles him — especially the microphone capability. “The spyware is a strong indicator that our government is very afraid of us,” he said. “They are ready to use whatever it takes to sabotage us because we’re currently the strongest and the most influential political force in Serbia.”

The March elections were plagued by violence and irregularities, he said. Still, he and fellow protesters are pressing on, aiming to win in the parliamentary elections expected this fall.

“I want to send a clear message that I am not afraid and that my colleagues are not afraid,” Rašić said. “We want justice, and I think the most important message is that students will win.”

An MP steps forward

On Wednesday, opposition parliamentarian Radomir Lazović of the Green-Left Front revealed his phone was among the 14 targeted. Forensic work to determine whether the attack succeeded is ongoing, per the SHARE Foundation.

Lazović called on the European Commission in March to act against Serbian President Aleksandar Vučić over rights abuses. The attacks on him and the students show “how [the government] are slipping into some sort of, I don’t know, dictatorship,” he said.

“They want to control the political opponents of the ruling party, which tells you what atmosphere we, as an opposition, are actually working in,” Lazović added. “If they are controlling us, if they’re monitoring us, and they’re tapping our phones and so on, it’s really hard to have any kind of meaningful opposition working in Serbia.”

Ó Cearbhaill warned that such attacks tend to spike around heightened political moments. With early parliamentary elections likely in October, he said, “we are increasingly concerned about the safety of student protesters and civil society in general.”

Continue Reading

Trending