Full Report
Specializing in AI-powered phishing-as-a-service and Android malware capable of intercepting OTP codes, the GXC Team targets Spanish bank users and 30 institutions worldwide
Analysis Summary
# Threat Actor: GXC Team
## Attribution & Identity
* **Actor Name:** GXC Team
* **Aliases:** None explicitly listed, but operates as a specialized developer and provider in the cybercrime underground.
* **Associations:** Operates under a **Phishing-as-a-Service (PhaaS)** model, providing tools to various cybercriminal affiliates.
## Activity Summary
The GXC Team is a sophisticated group currently targeting users of Spanish banking institutions and over 30 other financial organizations globally. They offer a comprehensive cybercrime kit that leverages AI-powered phishing pages and specialized Android malware designed to circumvent modern security measures like Two-Factor Authentication (2FA). Their recent operations involve high-fidelity clones of banking portals to harvest credentials and distribute malicious applications.
## Tactics, Techniques & Procedures
* **AI-Powered Phishing:** Utilization of AI to generate convincing, localized, and error-free phishing content to increase victim conversion rates.
* **OTP Interception:** Deployment of Android malware specifically engineered to intercept One-Time Password (OTP) codes from SMS and system notifications.
* **Social Engineering:** Impersonating bank security or technical support to trick users into downloading malicious APKs.
* **Man-in-the-Middle (MitM) / Proxying:** Using sophisticated phishing kits that can proxy traffic between the victim and the legitimate bank in real-time.
* **MITRE ATT&CK IDs:**
* **T1566.002:** Phishing: Spearphishing Link
* **T1474:** Supply Chain Compromise (via PhaaS model)
* **T1636.004:** Mobile Device Data Discovery: SMS Messages
* **T1557:** Adversary-in-the-Middle
## Targeting
* **Sectors:** Financial Services and Banking.
* **Geography:** Primarily **Spain**, with additional targets in the United Kingdom, Germany, Australia, and 30+ institutions worldwide.
* **Victims:** Users of institutions including (but not limited to):
* Laboral Kutxa
* Caixa Enginyers
* BBVA
* Banco Sabadell
* ING
* Hanseatic Bank
* Santander
* Unicaja
* Binance (Cryptocurrency)
## Tools & Infrastructure
* **Malware Families:**
* **GXC Android Bot:** A custom malware designed for SMS interception and credential theft.
* **Infrastructure:**
* **Defanged Phishing Domains:**
* aeginyers[.]com
* tuscamino[.]com
* cancelacion-transferencias[.]net
* es-entra[.]online
* laboralkutxa[.]es-users[.]com
* hanseaticsbank-da[.]com
* bancaminos-es[.]online
* bbvaempresa-es[.]com
* uk-lives[.]su
* z-sms[.]online
* binacefull[.]net
* **Malicious APK SHA-256 Samples:**
* 402544C3C74924C7A9F355108F474FD3B0D643A38ABA45C933D880B1C2A206DE
* E65C24D6E5F883CA02F79EDC0BD4FDBD28DC130F11FDBCA75B7FD26B2587BFA4
* **Signing Certificate:** 492682F877607EE99DF2DDD2BD5953FD727BDF6E19D397DE9DBBAFD582BCAD75
## Implications
The GXC Team represents an evolution in "commoditized" cybercrime. By integrating AI into Phishing-as-a-Service, they lower the barrier to entry for low-skilled attackers while maintaining high success rates. Their focus on OTP interception renders standard SMS-based 2FA ineffective, posing a significant strategic threat to financial institutions that rely solely on SMS for transaction authorization.
## Mitigations
* **Multi-Factor Authentication (MFA):** Shift from SMS-based OTPs to hardware tokens (FIDO2) or app-based push notifications that are harder to intercept.
* **Mobile Security:** Implement Mobile Threat Defense (MTD) solutions to detect sideloaded APKs and malicious SMS interception activity.
* **Domain Monitoring:** Proactively monitor and take down typosquatting and lookalike domains (e.g., those using .su, .online, or .club TLDs).
* **User Education:** Conduct awareness campaigns specifically highlighting that banks will never ask users to download an ".apk" file via SMS to resolve a security issue.