Law enforcement agencies from several countries have managed to dismantle the infrastructure of LabHost , a popular phishing-as-a-service (PhaaS) platform . They have also arrested 37 suspects , including the original developer .

The phishing platform launched in 2021 and allowed cybercriminals to carry out effective attacksusing a variety of phishing kits targeting banks and services in North America. Criminals paid a monthly subscription fee to use the service.
LabHost also provided infrastructure for hosting phishing pages and automatically creating and distributing phishing emails. These capabilities allowed criminals without much knowledge to carry out effective attacks.
See also: Brand impersonation: The 10 brands most used in phishing attacks in 2024
In February 2024, Fortra warned that LabHost was experiencing major development.
LabHost, as a Phishing-as-a-Service (PhaaS) platform, had significantly impacted the cybersecurity, as it had increased the accessibility and effectiveness of phishing attacks.
By providing an easy-to-use tool for creating and managing phishing campaigns, LabHost had enabled even more criminals to exploit people's inability to recognize and avoid attacks.
Additionally, criminals have been able to increase the scale and speed of their attacks, making phishing an even more significant cybersecurity threat.
See also: FBI: Massive wave of SMS phishing attacks for tolls
However, thanks to a recent international law enforcement operation, the service’s infrastructure was breached. The police operation began about a year ago. It was coordinated by Europol and involved police forces and specialist investigators from 19 countries, as well as private sector partners such as Microsoft, Trend Micro, Chainalysis, Intel 471 and The Shadowserver Foundation.

“ The investigation revealed at least 40,000 phishing domains linked to LabHost, with approximately 10,000 users worldwide ,” Europol said in a statement
Europol pointed to a particularly powerful tool called LabRat that set the service apart from the competition. LabRat is a real-time phishing management tool that allowed attackers to steal two-factor authentication (2FA) tokens and bypass account protections.
Between April 14 and 17, 2024, police forces carried out simultaneous searches at 70 addresses, arresting 37 people believed to be linked to the LabHost phishing service .
The Joint Policing Cybercrime Coordination Centre (JPC3) in Australia took down 207 servers hosting phishing websites created through the LabHost service.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Phishing attacks target activists
In the United Kingdom, Police announced that they had arrested four people involved in managing the service's website along with "the original developer of the platform."
The shutdown of LabHost and the arrest of the suspects demonstrates the importance of international cooperation and continuous efforts to combat cybersecurity threats .
Source: www.bleepingcomputer.com
