GXC Team
GXC Team is a cybercrime group and crime-as-a-service (CaaS) operation dismantled by the Spanish Guardia Civil in May 2025 with assistance from Group-IB. The group was allegedly led by a 25-year-old Brazilian national using the alias GoogleXcoder. Reporting states that GXC Team emerged in 2023 and operated via Telegram and at least one Russian-speaking hacker forum, providing phishing kits, Android malware, AI-powered voice scam tools, and support services to other cybercriminals. The operation targeted banks, government entities, transportation organizations, e-commerce organizations, and online shops. Victims were reported in Spain, Slovakia, the United Kingdom, the United States, and Brazil. The phishing kits cloned legitimate websites, including those of 10 Spanish banks and more than 30 international institutions and government portals, to steal credentials. The Android malware was described as disguising itself as a banking app and stealing OTPs by becoming the primary messaging app; other reporting describes it as an SMS-stealing Android trojan. The voice scam tooling used AI-generated calls to trick victims into disclosing 2FA codes. Group-IB reported identifying more than 250 fake scam sites and nine malware types tied to the infrastructure. The tools were marketed through underground channels, including a Telegram group reportedly named "Steal everything from grandmas." Authorities stated the campaigns caused millions in losses over the past year. Spanish authorities conducted six searches across Spain, arrested the alleged mastermind in San Vicente de la Barquera, Cantabria, detained other criminals using the tools, seized electronic devices containing source code, communications, and financial records, deactivated Telegram channels associated with the operation, and recovered stolen funds moved through digital currencies. Known alias directly mentioned in the content: GoogleXcoder (alleged leader/operator associated with GXC Team).
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Banks
- Government & Administration
- Consumer Discretionary Distribution & Retail
- Transportation
Where they target
Geographies tied to known operations.
- 🇧🇷 Brazil
- 🇸🇰 Slovakia
- 🇪🇸 Spain
- 🇺🇸 United States
- 🇬🇧 United Kingdom
Where they're from
Attributed origin per open-source reporting.
- BR
Tradecraft
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Crime-as-a-service platform distributing AI-powered phishing kits, Android malware, and voice-scam tooling.
GXC Team operated a Crime-as-a-Service (CaaS) network, selling phishing kits, Android malware, and AI-powered voice scam tools to facilitate large-scale financial fraud targeting banks, transportation companies, and online shops across multiple countries.
GXC Team is a crime-as-a-service group providing AI-powered phishing kits, Android malware, and scam tools to cybercriminals targeting financial and e-commerce sectors across multiple countries.
GXC Team operated a phishing-as-a-service platform capable of bypassing 2FA and included Android malware for targeting banks and crypto services, serving the Spanish-speaking cybercrime underground.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.