Federal authorities and Dutch law enforcement moved against a prolific spam and malware distribution operation based in Pakistan this week, taking control of dozens of servers and domains. Operating under the collective moniker "The Manipulaters," the group's proprietors have drawn attention in security reporting since 2015. The FBI identified organized crime syndicates as the primary users of the service, which they leveraged to deceive companies into transferring funds to accounts under the criminals' control.

On January 29, the FBI and Dutch national police targeted the technical backbone of a cybercrime marketplace known by the brands Heartsender, Fudpage and Fudtools, along with numerous other "fud" branded variations. The acronym "fud" denotes "Fully Un-Detectable," describing malicious tools engineered to evade detection by antivirus systems and anti-spam filters.

The Dutch police reported the seizure of 39 servers and domains, which harbored millions of victim records from across the globe—at minimum 100,000 records belonging to Dutch residents.

The U.S. Department of Justice identified the cybercrime operation by the pseudonym Saim Raza, a name The Manipulaters employed collectively when advertising their offerings on social media platforms. According to the DOJ, "The Saim Raza-run websites operated as marketplaces that advertised and facilitated the sale of tools such as phishing kits, scam pages and email extractors often used to build and maintain fraud operations."

Heartsender served as the operation's flagship product—a spam distribution platform that openly promoted phishing kits designed to target users of major internet services including Microsoft 365, Yahoo, AOL, Intuit, iCloud and ID.me.

Transnational organized crime organizations purchasing these services predominantly deployed them to execute business email compromise attacks, in which perpetrators deceived victim organizations into directing payments to accounts controlled by the criminals. The DOJ elaborated: "Those payments would instead be redirected to a financial account the perpetrators controlled, resulting in significant losses to victims. These tools were also used to acquire victim user credentials and utilize those credentials to further these fraudulent schemes. The seizure of these domains is intended to disrupt the ongoing activity of these groups and stop the proliferation of these tools within the cybercriminal community."

Years of Visibility

Manipulaters advertisement for “Office 365 Private Page with Antibot” phishing kit sold via Heartsender. “Antibot” refers to functionality that attempts to evade automated detection techniques, keeping a phish deployed and accessible as long as possible. Image: DomainTools.

KrebsOnSecurity initially documented The Manipulaters in May 2015, driven by their aggressive advertising across major cybercrime forums and their remarkably open approach to their illicit activities.

The group resurfaced in reporting during 2021 when core members established a web development company called WeCodeSolutions in Lahore, apparently to legitimize their substantial Heartsender earnings. The company's employees publicly exposed themselves by sharing photographs from annual company celebrations on Facebook, featuring cakes decorated with "FudCo" written in icing.

A subsequent article about The Manipulaters prompted communications from WeCodeSolutions staff requesting removal of the coverage. The individual using the Saim Raza identity claimed recent release from detention following arrest and charges by local authorities, though declined to provide specifics regarding the charges.

The group demonstrated consistent indifference toward concealing their own identities, which correlated with their failure to secure their customer base. An examination by DomainTools.com revealed that the web-hosted Heartsender platform exposed substantial user information to unauthenticated visitors, encompassing customer login credentials and internal employee email records.

Almost every year since their founding, The Manipulaters have posted a picture of a FudCo cake from a company party celebrating its anniversary.

DomainTools additionally identified that The Manipulaters' computers all carried identical password-stealing malware infections, with stolen credentials subsequently marketed online. The security firm observed: "Ironically, the Manipulaters may create more short-term risk to their own customers than law enforcement. The data table 'User Feedbacks' (sic) exposes what appear to be customer authentication tokens, user identifiers, and even a customer support request that exposes root-level SMTP credentials–all visible by an unauthenticated user on a Manipulaters-controlled domain."

Dutch authorities indicated that investigations into the service's operators and purchasers remain active. The Dutch national police stated: "The Cybercrime Team is on the trail of a number of buyers of the tools. Presumably, these buyers also include Dutch nationals. The investigation into the makers and buyers of this phishing software has not yet been completed with the seizure of the servers and domains."

Broader Enforcement Action

U.S. law enforcement coordinated with counterparts in Australia, France, Greece, Italy, Romania and Spain this week to seize domains associated with multiple long-established cybercrime marketplaces and forums, including Cracked and Nulled. Europol reported that these two communities collectively attracted more than 10 million registered users.

The coordinated operation, designated "Operation Talent," also resulted in the seizure of Sellix, an e-commerce platform frequently utilized by cybercrime forum participants to conduct transactions in illicit goods and services.

Source: Krebs on Security