Full Report
Group-IB takes part in a global operation to cripple Canadian Phishing-as-a-Service provider LabHost
Analysis Summary
# Incident Report: Global Takedown of LabHost Phishing-as-a-Service (PhaaS)
## Executive Summary
A massive international law enforcement operation, supported by Group-IB, resulted in the disruption of **LabHost**, a major Canadian-based Phishing-as-a-Service provider. The platform enabled over 2,000 cybercriminals to create sophisticated phishing pages targeting banks, government agencies, and digital services worldwide. The operation led to 37 arrests and the seizure of infrastructure that had facilitated the theft of approximately 480,000 credit card numbers and 1 million passwords.
## Incident Details
- **Discovery Date:** Investigation intensified throughout 2023–2024
- **Incident Date:** Takedown occurred mid-April 2024 (Platform active since 2021)
- **Affected Organization:** 40,000+ phishing domains created; targeting customers of major banks (RBC, CIBC, HSBC), Netflix, and government services (ATO, Canada Post).
- **Sector:** Phishing-as-a-Service (PhaaS) / Cybercrime Infrastructure
- **Geography:** Global (Primary operations based in Canada; infrastructure and arrests in UK and 18 other countries)
## Timeline of Events
### Initial Access
- **Date/Time:** 2021 (Launch of LabHost)
- **Vector:** Phishing-as-a-Service subscription model.
- **Details:** Attackers (subscribers) purchased monthly memberships (starting at ~$179 USD) to access "LabStat," a toolkit for deploying phishing pages via SMS (smishing) and email.
### Lateral Movement
- **N/A:** As a PhaaS provider, the platform moved "laterally" by expanding its template library to include over 170 fake websites, allowing attackers to pivot between different brands and industries effortlessly.
### Data Exfiltration/Impact
- **Volume:** 480,000 card numbers, 64,000 PINs, and over 1 million passwords stolen.
- **Targeting:** LabHost provided templates for financial institutions, telecommunications, and postal services.
### Detection & Response
- **Detection:** Group-IB and law enforcement monitored the "LabSend" tool and infrastructure.
- **Response:** Operation led by London’s Metropolitan Police and Europol, involving 19 countries. The website was seized and replaced with a law enforcement landing page.
## Attack Methodology
- **Initial Access:** Use of "LabSend" to blast SMS messages containing links to fraudulent domains.
- **Persistence:** High-availability hosting of phishing pages; automated domain rotation.
- **Privilege Escalation:** N/A (Focus was on credential harvesting).
- **Defense Evasion:** Use of diverse IP ranges (Linode, Plesk) and IDN (Internationalized Domain Names) homograph attacks to mimic legitimate URLs (e.g., using "rḅc.com").
- **Credential Access:** Real-time monitoring of victim interaction; bypass of Two-Factor Authentication (2FA) via "adversary-in-the-middle" (AiTM) techniques.
- **Discovery:** Automated scanning of target lists (emails/phone numbers).
- **Impact:** Financial fraud and identity theft at scale.
## Impact Assessment
- **Financial:** Multi-million dollar losses for victims globally; LabHost earned approx. $1.17M in subscription fees.
- **Data Breach:** High volume of PII (Personally Identifiable Information) and financial data compromised.
- **Operational:** Disruption of over 40,000 active phishing sites.
- **Reputational:** Erosion of trust in SMS-based communications from major banks and services.
## Indicators of Compromise
### Network Indicators (Defanged)
- hxxp://starbucksgreenapron[.]rest/deposit/rbc/
- hxxp://rbc-verify[.]ca/deposit/rbc/
- hxxp://mytoronto-pay[.]ca/to
- hxxp://pursuepackage[.]com/dh
- hxxps://secure[.]rḅc[.]com/deposit/rbc/
- hxxp://45[.]33[.]101[.]165/deposit/atb/
- hxxp://185[.]196[.]8[.]76[.]plesk[.]page/sut/
### File Indicators (LabSend Samples)
- **MD5:** c6aee94573d66d8742917129ae959d76
- **SHA-256:** 9314442e87f4e7ef386e75552e31baeac63e1fa4630834510e6cb43b0c50f783
## Response Actions
- **Containment:** Domain seizures and hosting account terminations.
- **Eradication:** Global law enforcement arrests of operators and high-volume "customers."
- **Recovery:** Notification of compromised users by affected financial institutions.
## Lessons Learned
- **Lowered Entry Barrier:** PhaaS allows low-skilled actors to launch sophisticated, multi-factor-aware campaigns.
- **Infrastructure Weaknesses:** Reliance on common hosting providers (Linode, Plesk) allowed investigators to track and cluster malicious activity.
- **Collaboration Success:** The scale of the takedown demonstrates that public-private partnerships (Group-IB and Europol/Met Police) are essential for dismantling global cybercrime hubs.
## Recommendations
- **MFA Hardening:** Transition from SMS-based 2FA to hardware keys (FIDO2) or app-based authenticators to prevent AiTM interception.
- **Brand Monitoring:** Organizations should employ Digital Risk Protection (DRP) to detect and takedown lookalike domains in real-time.
- **User Training:** Educate customers to never click links in unexpected SMS messages ("Smishing"), even if the sender ID appears legitimate.