Full Report
Analyze Tajin Group's role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations.
Analysis Summary
# Threat Actor: Tajin Group (踏金集团)
## Attribution & Identity
- **Actor Identification:** Tajin Group is a prominent third-party vendor and service provider active within the Chinese-language cybercrime ecosystem.
- **Aliases:** Tajin Group, 踏金集团 (Tà Jīn Jítuán).
- **Associated Groups/Platforms:**
- Operates primarily through **Telegram**.
- Affiliated with Chinese-language "Guarantee Marketplaces" (担保网), specifically **Dabai Guarantee** (大白担保) and **Xinbi Guarantee** (信币担保).
- Utilizes **Fragment Market** for anonymous operational infrastructure.
## Activity Summary
Tajin Group is a specialized financial crime syndicate that bridges the gap between technical exploits and money laundering. They offer "guarantee" services for illicit transactions, manage phishing campaigns, and operate complex cash-out schemes. Recently, the group has shifted its operations from Dabai to Xinbi Guarantee, indicating a lack of platform loyalty and an adaptive business model. Their current focus involves exploiting Middle Eastern and international payment gateways to drain stolen card data (CC) and facilitate cross-border money laundering.
## Tactics, Techniques & Procedures
- **Phishing & Carding:** Recruitment and deployment of phishing kits to harvest payment card data, specifically targeting Bank Identification Numbers (BINs) from multiple global regions.
- **Payment Gateway Exploitation:** Bypassing security controls (2D/3D Secure) on payment platforms such as **CCAvenue** and **Geidea**.
- **Financial Testing:** Systematic small-amount testing on cards to verify "overnight" (隔夜) card status and bypass bank fraud controls.
- **Operational Security (OPSEC):**
- Use of **Fragment Market** to purchase anonymous virtual numbers and Telegram usernames to avoid SIM-based tracking.
- Deployment of "Remote Control" (远控) and "Sync Disks" (同步盘) for managing overseas victim data.
- **Money Laundering:** Utilizing UAE Dirhams (AED), electronic gift cards, and cryptocurrency to obfuscate the origin of stolen funds.
- **Service Integration:** Offering "Cloud Deductions" (云扣), balance inquiries, and direct payment channels (UnionPay, VISA, Mastercard, Apple Pay).
## Targeting
- **Sectors:** Banking, Fund Transfer Services, E-commerce, Cryptocurrency Exchanges.
- **Geography:**
- **Primary Victims:** Mainland China citizens and banks.
- **Global Operations:** Philippines, Sri Lanka, Vietnam, South Africa, UK, Romania, UAE, Pakistan, Bangladesh, Malaysia, and various EU/Latin American countries.
- **Victims:** Cardholders at banks including (but not limited to) BDO Unibank, Lloyds Bank PLC, HSBC UK, ING Romania, Standard Bank (South Africa), and Bank of China (Philippines).
## Tools & Infrastructure
- **Malware:** Overseas remote control tools (远控), phishing kits, and data synchronization software.
- **Infrastructure:**
- **Telegram Channels:** @tjjt_gx (Supply and Demand Channel).
- **Defanged Domains/URLs:**
- hxxps[://]payae[.]cc/QTTb209
- hxxps[://]payae[.]cc/Qwpf734
- ccavenue[.]ae (Exploited merchant gateway)
- **Merchant Accounts:** SUNWEL ENTERPRISE TRADING LLC (identified as a front for CCAvenue exploitation).
## Implications
Tajin Group represents the professionalization of the Chinese cybercrime underground. By operating as a "guarantee" vendor, they lower the barrier to entry for other criminals, acting as a force multiplier. Their ability to adapt to different payment gateways and their sophisticated use of anonymous Telegram infrastructure suggest they are highly resilient to traditional law enforcement takedowns. Their global reach indicates that financial institutions worldwide, not just in China, are at risk from their card-testing and laundering operations.
## Mitigations
- **BIN Monitoring:** Financial institutions should monitor for high-frequency, low-value "testing" transactions associated with the BINs listed in the group's active manifests.
- **Gateway Security:** Payment processors (like CCAvenue and Geidea) should implement stricter velocity checks and merchant vetting, particularly for entities involving high-risk regions or UAE Dirham transfers.
- **Telegram Intelligence:** Organizations should monitor Telegram-based guarantee marketplaces for mentions of their brand or specific card headers.
- **Enhanced Authentication:** Implementation of robust 3D Secure (3DS) protocols and multi-factor authentication to counter "2D" bypass techniques used by Tajin Group.