The phishing-as-a-service platform BulletProftLink (PhaaS) that provided more than 300 phishing templates has been seized according to the Malaysian Police .

The phishing operation began in 2015, but was later discovered by researchers. It became more active in 2018 and had thousands of subscribers.
PhaaS platforms provide cybercriminals with tools and resources to conduct phishing attacks through ready-made kits and templates. They also provide hosting of malicious pages, credential harvesting capabilities, and reverse proxying tools.
The BulletProftLink phishing operation has been examined by researchers in the past. In 2020, a cybersecurity expert, Gabor Szathmari, conducted an investigation and linked the operator of the service to a Malaysian national who was living a luxurious life.
See also: Iranian hackers MuddyWater target Israel through spear-phishing
Additionally, a Microsoft report in September 2021 warned about the was enabling service, and the large number of phishing templates available to buyers. The service was also collecting all the credentials stolen from its subscribers (1,618 at the time) in phishing attacks.
BulletProftLink was destroyed
With the help of the Australian Federal Police and the FBI, Malaysian police were able to dismantle the phishing operation and take down several domains.
Police arrested eight people on November 6. One of them is believed to be the ringleader of the operation. Authorities also seized cryptocurrency wallets with about $213,000, servers, computers, jewelry, vehicles and payment cards.

Once the servers are seized, law enforcement can examine them to identify the platform’s users. It’s worth noting that some of them were paying a $2,000/month subscription fee for access to credentials logs. Intel471 says that as of April 2023, the BulletProftLink phishing service had 8,138 active subscribers with access to 327 phishing page templates. This number of users represents a 403% increase over the number Microsoft reported in 2021. This shows how popular the service had become in about two years.
Intel 471 says that the phishing resources offered by BulletProftLink before its removal “included login pages for Microsoft Office, DHL, South Korea-based online platform Naver, and financial institutions such as American Express, Bank of America, Consumer Credit Union, and Royal Bank of Canada.”
See also: 1265% increase in phishing emails: The role of ChatGPT
Some of these phishing pages were hosted on legitimate cloud, such as Google Cloud and Microsoft Azure, to avoid detection by email security tools.
BulletProftLink also offered the Evilginx2 reverse-proxying tool that enables adversary-in-the-middle (AITM) phishing attacks, which can bypass multi-factor authentication protections.
The BulletProftLink phishing service helped cybercriminals gain initial access to corporate systems. Its seizure will leave a major gap in the market.
However, phishing attacks continue. Therefore, users and organizations who want to protect themselves should follow some basic security:
Individuals and organizations can take steps to protect themselves from large-scale phishing attacks. One of the most important measures is user education and awareness. People need to be aware of the techniques used by malicious users and learn to recognize suspicious emails and websites.

Also, people should avoid responding to requests for personal information or financial details via email or social media messages
See also: The use of QR codes in phishing attacks is increasing
Additionally, organizations must implement strict security policies, such as using complex passwords, updating and strengthening security software, and periodically training employees.
Using reliable security and anti-phishing software can also help identify and block malicious messages and websites.
Finally, keeping software up-to-date is vital to protect against vulnerabilities that attackers can exploit.
Source: www.bleepingcomputer.com
