HeartSender, also known as The Manipulaters, is a Pakistan-based cybercrime group and illicit service provider focused on phishing, malware dissemination, and fraud enablement. The group became known for selling phishing kits and phishing templates, operating infrastructure that supported phishing campaigns, and maintaining a marketplace for stolen credentials. Reporting has linked the operation to substantial financial losses in the United States, exceeding $50 million. HeartSender functioned as a criminal service ecosystem rather than a single isolated intrusion set, enabling credential theft and broader fraud activity through commoditized tooling. Its operations included the distribution of phishing toolkits, support for malware-enabled theft, and the sale of compromised account data. Law enforcement action against the group included arrests in Pakistan and coordinated infrastructure seizures by U.S. and Dutch authorities. The actor’s observed behavior supports assessment of capabilities in initial access through phishing, credential theft, malware-enabled post-compromise activity, and exfiltration of stolen data and credentials for resale. The group’s dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operated a phishing and malware dissemination service, facilitating cybercrime operations globally.
HeartSender is a criminal group operating phishing and fraud toolkits, with a physical presence in Pakistan.
HeartSender is a cybercriminal group specializing in phishing operations, selling phishing kits and templates, and running a marketplace for stolen credentials. They have caused significant financial losses, particularly in the US.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.