FishingMaster, also known by its Chinese name 垂钓大师, is a China-based phishing-as-a-service (PhaaS) platform associated with industrialized phishing operations targeting Japanese brands. It has been linked to the CoGUI phishing campaign and provides operational infrastructure that lowers the barrier to entry for phishing activity. Reported targeting has included organizations and brands in the financial, transportation, and government service sectors in Japan. The platform has been described as operating through closed distribution and promotion channels, which limited public visibility into its ecosystem. Following public exposure in 2025, the operators reportedly suspended activity temporarily and later resumed under rebranded names including NX and FA. Subsequent operations were characterized by improved operational security measures, including greater infrastructure concealment, encrypted communications, and stronger detection evasion. FishingMaster appears to support scalable phishing operations through centralized administration and service delivery typical of mature PhaaS ecosystems. Associated phishing infrastructure has been noted to rely on characteristic URL and API patterns, and the broader ecosystem around such platforms commonly includes phishing site creation and configuration, stolen-data management, cloaking, domain management, and OTP-bypass functionality. The actor’s behavior is consistent with financially motivated cybercrime focused on credential harvesting and related post-compromise monetization rather than espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.