SIMCARTEL is a criminal SIM-box network dismantled by European law enforcement in connection with large-scale fraud and abuse of telecommunications infrastructure. The operation was linked to thousands of fraud cases and multimillion-euro losses. The network operated extensive SIM-box infrastructure and large volumes of SIM cards to provide rentable phone numbers at scale, enabling criminal users to bypass platform controls, automate account creation, and support anonymous or disposable communications across many countries. The service facilitated phishing and smishing campaigns, investment fraud, impersonation schemes, marketplace scams, fake online shops, messaging-app scams, and extortion. It was also used to create tens of millions of fraudulent online accounts. The actor’s tradecraft centered on telecommunications abuse and criminal enablement rather than bespoke malware operations, using SIM-boxes and rented numbers as infrastructure for fraud, spoofing, and large-scale scam activity. Arrests associated with the network included Latvian nationals, indicating an operational nexus to Latvia. The broader investigation remained ongoing to determine the full scope of the network and its criminal customers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.