Full Report
Fraud-as-a-Service operation targeting Dutch residents
Analysis Summary
# Threat Actor: Fraud Family
## Attribution & Identity
* **Actor Name:** Fraud Family
* **Identification:** An organized Fraud-as-a-Service (FaaS) group operating a sophisticated affiliate model.
* **Aliases/Panel Names:** "Reliable Admin" (name associated with an updated 2021 version of their administrative panel).
* **Known Associations:** The group operates as a provider for multiple "affiliates" or sellers who carry out the actual attacks using the group's central infrastructure.
## Activity Summary
Fraud Family is a cybercriminal collective that facilitates large-scale phishing and financial fraud. They provide a comprehensive infrastructure—including phishing kits and backend administrative panels—to affiliates who target residents of the Netherlands. Their operations have evolved over time, notably updating their backend systems (e.g., the transition to the "Reliable Admin" panel in 2021) to streamline fraudulent activities and credential harvesting.
## Tactics, Techniques & Procedures
* **Fraud-as-a-Service (FaaS):** Providing ready-made phishing infrastructure to lower-level cybercriminals.
* **Phishing & Smishing:** Delivery of malicious links via SMS or email impersonating trusted organizations.
* **Brand Impersonation:** Detailed spoofing of Dutch financial institutions and official services.
* **URL Obfuscation:** Heavy use of URL shorteners to mask malicious destinations (e.g., `bit[.]ly`, `s[.]id`, `tny[.]sh`).
* **Credential Harvesting:** Real-time interception of banking credentials and personal information through customized landing pages.
* **Adversary-in-the-Middle (AiTM) / Live Interaction:** Use of administrative panels to interact with victims in real-time to bypass security measures.
## Targeting
* **Sectors:** Financial Services, Banking, and Government/Public Services.
* **Geography:** Primarily the Netherlands (Dutch residents).
* **Victims:** Customers of leading Dutch financial organizations and individuals targeted through local delivery or service scams.
## Tools & Infrastructure
* **Malware/Kits:** Custom Phishing Kits (including the "Reliable Admin" backend).
* **Infrastructure:**
* Administrative panels for real-time fraud management.
* Third-party URL shortening services.
* Domains mimicking official Dutch banking and service portals (specific domains defanged: `bit[.]ly`, `s[.]id`, `tny[.]sh`).
## Implications
Fraud Family represents a professionalized tier of cybercrime that scales attacks by empowering numerous affiliates. Their focus on a specific geographic region (the Netherlands) allows them to refine their lures (language, branding) for high success rates. The use of real-time administrative panels indicates a capability to bypass multi-factor authentication (MFA) or other session-based security controls by interacting with the victim while they are active on the phishing site.
## Mitigations
* **User Education:** Educate users to identify URL shortener abuse and verify communication through official channels.
* **Domain Monitoring:** Organizations should monitor for typosquatting and brand impersonation domains.
* **Incident Reporting:** Victims should report incidents to `fraudehelpdesk[.]nl` or `scamadviser[.]com`.
* **Technical Verification:** Use tools like `URLScan[.]io` or `VirusTotal` to analyze suspicious links before clicking.
* **Enhanced Authentication:** Implementation of hardware-based MFA (like FIDO2) which is more resilient to the AiTM/phishing kit tactics used by groups like Fraud Family.