Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to threat actors

Prince Holding Group

Also known asPrince Holding Group

Prince Holding Group is a Cambodia-based conglomerate that U.S. authorities have alleged functioned as a transnational criminal organization under the leadership of founder and chairman Chen Zhi, also known as Vincent. According to the provided reporting, prosecutors allege the group has overseen since at least 2015 the operation of at least 10 scam compounds in Cambodia that used trafficked laborers and forced labor to conduct large-scale cryptocurrency investment fraud, including pig butchering and romance-style scams. Reported tradecraft includes initial contact over social media and messaging platforms, including wrong-number scripts, grooming victims into false relationships, and then inducing them to send funds or invest in fraudulent cryptocurrency schemes. The content also states that coercion, captivity, isolation, beatings, and other violence were used against workers in the compounds, including at sites associated with the Jinbei Casino Hotel and Golden Fortune. The group is further alleged to have laundered proceeds through Prince Holding Group businesses and related entities, including hotels, casinos, online gambling, financial services, cryptocurrency mining, shell companies, and offshore hubs in Singapore, Hong Kong, the British Virgin Islands, and the Cayman Islands, using techniques described as spraying and funneling. The U.S. Treasury designated Prince Holding Group as a transnational criminal organization, and U.S. and UK authorities imposed sanctions on the group, Chen Zhi, and numerous related entities and executives. Known alias in the provided content: prince_holding_group.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • crypto
  • finance
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.