Ratted Out: Group-IB contributes to Operation DISTANTHILL leading to the arrest of 16 cybercriminals behind the Android Remote Access Trojan campaigns resulting in over US$25 million in financial losses across Southeast Asia

Group-IB, a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime, announced today that it contributed to a joint operation by the Singapore Police Force (SPF), the Hong Kong Police Force (HKPF) and the Royal Malaysia Police (RMP). Dubbed “Operation DISTANTHILL”, it culminated in the arrest of the cyber fraud syndicates that were responsible for an Android Remote Access Trojan (RAT) campaign which gained notoriety in Singapore and Hong Kong in 2023. In the lead-up to the operation, Group-IB spent months collecting and analysing the data derived from the Android trojans, uncovering the scale of the cybercriminals network used for attacks and its administrators. More than 4,000 victims were defrauded across Southeast Asia. Among them, the Singapore police recorded 1,899 related cases in 2023 with a total loss of more than US$25 million.

As part of “Operation DISTANTHILL”, the HKPF apprehended 10 men and 4 women aged between 19 to 61 years old on charges of conspiring fraud and money laundering. In-depth analysis revealed at least 260 variants of the Remote Access Trojan stored on command and control (C2) servers in Hong Kong and other Southeast Asian countries. Between 12 to 13 June 2024, 2 men in Malaysia aged 26 and 47, suspected to be the main culprits behind the cyber-attacks and controllers of more than 50 servers used in the attack, were arrested in a joint cross-border operation led by the SPF and including the HKPF and the RMP.

During the course of investigating these campaigns, Group-IB’s High-Tech Crimes Investigation unit discovered that this Remote Access Trojan (RAT) targeted Android users through phishing campaigns, enticing victims to download and install fake apps onto their mobile devices. Based on Group-IB’s High-Tech Crime Trends Report 2023/2024, these apps were often disguised as offering special prices for goods and food items. Once installed and necessary permissions granted, the RAT allows threat actors remote control over the Android device, enabling them to capture sensitive personal data and passwords using its keylogger and screen capture functions. The RAT allowed threat actors to monitor SMS, containing one-time passwords (OTP) sent by financial organisations as a second factor authentication.  Furthermore, the RAT facilitated real-time geolocation tracking of the device and its user. Operating discreetly in the background, it persists even after the Android device is rebooted. The same trojan has been advertised as a malware-as-a-service scheme, which has also claimed victims in different parts of the world, including the Middle East and Europe.

Group-IB’s High-Tech Crime Investigations played a pivotal role in the operation by analyzing the malware-as-a-service campaign of the Android trojan used in the attacks and threat actors who advertised the service. Group-IB specialists tracked the settings of over 250 phishing web pages, which facilitated the spread of fake Android apps. It also helped to find indicators of the phishing administrators, as well to provide insights into the scale of the attacks and their victims. Employing Group-IB’s patented Graph Network Analysis technology, Group-IB specialists correlated command and control (C2) servers from over 100 malware samples, to paint a comprehensive picture of threat actor’s network infrastructure and  operators behind the scheme.

A screenshot of Group-IB’s Graph Network Analysis technology used in the investigation

A screenshot of Group-IB’s Graph Network Analysis technology used in the investigation

“We are delighted to contribute to “Operation DISTANTHILL” and the dismantling of the malicious Android Trojan campaign. This successful operation is a testament to the power of collaboration between law enforcement agencies and the private sector in the fight against digital threats. Through our worldwide network of Digital Crime Resistance Centers (DCRCs), including in Singapore, we are able to offer tailored solutions to address cybersecurity threats that are unique to our local client, businesses, and their customers. We encourage others to join us in fighting cybercrime, and by pooling our resources, expertise, and technology, we can strengthen global cybersecurity. This partnership underscores our shared mission to relentlessly pursue cybercriminals and protect individuals and businesses from evolving threats, reinforcing the vital importance of public-private collaboration in securing our digital future.”

Dmitry Volkov
Dmitry Volkov

CEO of Group-IB

“Group-IB’s dedication to cybersecurity, as a member of the Cyber Security Action Task Force (CSATF) established by the Hong Kong Police Force (HKPF), reflects the collective effort of both public and private sectors in safeguarding our digital landscape. This collaboration unites to fortify our defences against evolving cyber threats. Through the rapid exchange of threat intelligence and knowledge sharing, it is ensured that a secure cyber environment for all. Group-IB’s invaluable contributions exemplify the spirit of cooperation essential in this endeavour.”

Chief Inspector CHENG

Hong Kong Police Force

Group-IB is an APPACT partner of SPF and was recognized for its contributions to investigations in 2022 and 2023. Since 2024, Group-IB has been a member of HKPF Cyber Security TaskForce.

About Group-IB

Founded in 2003 and headquartered in Singapore, Group-IB is a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime. Combating cybercrime is in the company’s DNA, shaping its technological capabilities to defend businesses, citizens, and support law enforcement operations.

Group-IB’s Digital Crime Resistance Centers (DCRCs) are located in the Middle East, Europe, Central Asia, and Asia-Pacific to help critically analyze and promptly mitigate regional and country-specific threats. These mission-critical units help Group-IB strengthen its contribution to global cybercrime prevention and continually expand its threat-hunting capabilities.

Group-IB’s decentralized and autonomous operational structure helps it offer tailored, comprehensive support services with a high level of expertise. We map and mitigate adversaries’ tactics in each region, delivering customized cybersecurity solutions tailored to risk profiles and requirements of various industries, including retail, healthcare, gambling, financial services, manufacturing, crypto, and more.

The company’s global security leaders work in synergy with some of the industry’s most advanced technologies to offer detection and response capabilities that eliminate cyber disruptions agilely.

Group-IB’s Unified Risk Platform (URP) underpins its conviction to build a secure and trusted cyber environment by utilizing intelligence-driven technology and agile expertise that completely detects and defends against all nuances of digital crime. The platform proactively protects organizations’ critical infrastructure from sophisticated attacks while continuously analyzing potentially dangerous behavior all over their network.

The comprehensive suite includes the world’s most trusted Threat Intelligence, The most complete Fraud Protection, AI-powered Digital Risk Protection, Multi-layered protection with Managed Extended Detection and Response (XDR), All-infrastructure Business Email Protection, and External Attack Surface Management.

Furthermore, Group-IB’s full-cycle incident response and investigation capabilities have consistently elevated industry standards. This includes the 77,000+ hours of cybersecurity incident response completed by our sector-leading DFIR Laboratory, more than 1,400 successful investigations completed by the High-Tech Crime Investigations Department, and round-the-clock efforts of CERT-GIB.

Time and again, its solutions and services have been revered by leading advisory and analyst agencies such as Aite Novarica, Gartner®, Forrester, Frost & Sullivan, KuppingerCole Analysts AG, and more.

Being an active partner in global investigations, Group-IB collaborates with international law enforcement organizations such as INTERPOL, EUROPOL and AFRIPOL to create a safer cyberspace. Group-IB is also a member of the Europol European Cybercrime Centre’s (EC3) Advisory Group on Internet Security, which was created to foster closer cooperation between Europol and its leading non-law enforcement partners.