A court in Singapore has jailed a man for helping cybercriminals carry out malware attacks through tutorials and other guides. In a way, he was acting like a teacher.

According to local media, the 49-year-old man was sentenced to five and a half years in prison and fined S$3,608 (US $2,700) after admitting to creating detailed video tutorials showing members of a criminal gang how to infect Android phones with spyware and empty their bank accounts. Cheoh Hai Beng, a Malaysian national, was recruited by a cybercrime gang to act as a trainer rather than a direct con artist.
See also: Gentlemen ransomware compromises corporate networks to intercept and encrypt sensitive data
49-year-old was teaching malware courses
His role was to provide step-by-step explanations on how to deploy and operate the Spymax remote access trojan (RAT) on Android devices. Between February and May 2023, he allegedly recorded around 20 instructional videos showing how the malware could be installed, controlled, and used to silently seize control of victims' smartphones.
The videos showed how to set up the spyware and exploit its capabilities, including remotely accessing cryptocurrency apps and logging wallet codes , taking over the smartphone camera, collecting address books , and tracking the device's location via GPS
See also: Phantom Stealer: Phishing attack with ISO images targets Russia
Reports of Spymax date back to at least 2019, but its popularity increased during the pandemic, when attackers tricked unsuspecting users into installing tracking apps COVID-that actually contained malware.

Spymax malware
Spymax allowed remote cybercriminals to monitor phone conversations (both voice and text), record passwords, access banking applications , and even control infected devices in real time . Once installed, Spymax RAT allowed financial transactions without victims being aware of it.
Researchers say the lessons used to train gang members were shared across criminal networks, with victims typically tricked into installing the malware via phishing emails or fake download links posing as legitimate software or services.
See also: VolkLocker ransomware allows free decryption

According to Singaporean authorities, this is the country’s first prosecution specifically targeting someone who taught others how to use malware. They allege that Cheoh was first introduced to the spyware through an acquaintance, Taiwanese national Lee Rong Teng, whom he had befriended in 2008 while serving a prison sentence in South Korea. Prosecutors allege that Lee Rong Teng provided Cheoh with several versions of the spyware and asked him to learn how it worked.
This week, Cheoh Hai Beng pleaded guilty to participating in a criminal gang and conspiring with others to use malicious software. Cheoh's alleged accomplice, Lee Rong Teng, is believed to remain at large.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
