Full Report
Law enforcement seized dozens of domains linked to a group known as Saim Raza, or HeartSender, which has been selling hacking tools since at least 2020.
Analysis Summary
# Threat Actor: Saim Raza / HeartSender
## Attribution & Identity
The cybercrime network is operated by an individual/group known as **Saim Raza**, also tracked as **HeartSender**. The operation is based in **Pakistan**. They are described as a professional cybercriminal group that has been active for nearly a decade and was among the first phishing-focused marketplaces to expand services across multiple branded shops.
## Activity Summary
Saim Raza/HeartSender operated an online network selling illicit hacking tools and compromised infrastructure access to thousands of customers worldwide since at least 2020. This operation was disrupted by U.S. and Dutch law enforcement agencies seizing dozens of associated domains. The primary use of the sold tools by customers was for executing Business Email Compromise (BEC) schemes. Independent journalist Brian Krebs first exposed the operation in 2021.
## Tactics, Techniques & Procedures
- Selling ready-made hacking tools (phishing kits, scam pages, email extractors).
- Providing instructional YouTube videos to train users with low technical expertise on tool deployment.
- Marketing tools as "fully undetectable" by antivirus software.
- Selling access to compromised infrastructure, including email servers, WordPress accounts, and control panels (cPanel).
- Customers use stolen credentials/tools to facilitate BEC schemes, successfully deceiving companies into unauthorized fund transfers.
## Targeting
- Sectors: General businesses targeted by BEC (implied by tool usage).
- Geography: Worldwide customer base; the U.S. operations alone resulted in millions in losses.
- Victims: Companies targeted by HeartSender customers via BEC schemes.
## Tools & Infrastructure
- Malware families used: Phishing kits, scam pages, email extractors.
- Infrastructure (C2, domains, IPs): The group operated numerous marketplaces/websites which were recently seized by law enforcement. Specific domain names were not listed but were seized.
## Implications
HeartSender actively fueled the cybercrime ecosystem by democratizing access to hacking capabilities, lowering the barrier to entry for less skilled criminals to execute sophisticated attacks like BEC. The operational security failures observed by researchers could potentially expose their customers as well. The disruption aims to halt the proliferation of widely available, "ready-to-use" cybercriminal tools.
## Mitigations
- Enhanced vigilance against high-volume spam and phishing campaigns, particularly those targeting credentials or fund transfers (BEC).
- Reviewing security posture related to web hosting control panels (cPanel) and WordPress installations for unauthorized access or lateral movement vectors.
- Organizations should monitor for evidence of their infrastructure access (email servers, cPanel accounts) being sold on underground marketplaces.