Cybersecurity researchers have shed light on two service providers that are supplying online criminal networks with the tools and infrastructure to fuel the PBaaS economy. Since at least 2016, Chinese-speaking criminal groups have established industrial-scale fraud hubs in Southeast Asia, creating special economic zones dedicated to investment and impersonation fraud.
See also: Microsoft: Incorrect email routing enables internal domain phishing

These facilities house thousands of people who are lured with the promise of high-paying jobs, only to have their passports confiscated and forced to commit fraud under threat of violence. INTERPOL has described these networks as fraud fueled by human trafficking on an industrial scale.
One of the key drivers of PBaaS (also known as romance baiting) scams is service providers that supply networks with tools to conduct and manage social engineering operations, as well as to quickly launder stolen funds and cryptocurrencies, transferring the illicit proceeds to accounts that cannot be traced by law enforcement.
“ Large fraud hubs like the Golden Triangle Economic Zone (GTSEZ) are now using ready-made applications and templates from PBaaS providers ,” Infoblox reported . “ In addition, what once required technical expertise or investment in physical infrastructure can now be purchased as an off-the-shelf service, offering everything from stolen identities and front companies to complete fraud platforms and mobile apps, dramatically lowering the barrier to entry. ” These services offer complete fraud packages and kits that lay the foundation for launching scalable online fraud operations with minimal effort.
See also: Instagram data leak: The platform says there was no breach

One such threat actor is Penguin Account Store , also known as Heavenly Alliance and Overseas Alliance . Penguin operates under a crimeware-as-a-service (CaaS) model, advertising scam kits, fraud templates, and “ shè gōng kù ” datasets that include stolen personal information belonging to Chinese citizens. The group also sells account data from various popular media platforms including Twitter, Tinder, YouTube, Snapchat, Facebook, Instagram, Apple Music, OpenAI ChatGPT, Spotify, and Netflix, among others.
These credentials are likely obtained through information theft files sold on the dark web.
It is currently unclear whether they operate as thieves themselves or simply act as intermediaries of stolen data for other threat actors. Prices for pre-registered social media accounts start at just $0.10 and increase depending on the date of registration and authenticity. Penguin also provides bulk pre-registered SIM cards, stolen social media accounts, 4G or 5G routers, IMSI catchers, and stolen image packs (character sets) used to trap victims.
See also: Phishing campaign targets Cardano users

Additionally, the threat actor has developed a Social Customer Relationship Management (SCRM) called SCRM AI to facilitate automated victim engagement on social media. The threat actor also advertises BCD Pay, a payment processing platform directly linked to Bochuang Guarantee (博创不创自), which is an anonymous peer-to-peer (P2P) solution similar to HuiOne, with deep roots in the illegal online gambling space.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
