K99 Group, also known as K99 Culture and Media Co Ltd, is a Cambodia-based scam-center network linked to industrialized online fraud and human trafficking. It has been identified as part of a broader criminal ecosystem associated with Cambodian political and business elites, including the wider network controlled by Kok An. The group has been tied to properties where trafficked individuals were forced to conduct fraud operations, including pig-butchering schemes targeting victims with fraudulent digital-asset investment opportunities. Entities linked to K99 Group have been associated with scam compounds in Cambodia that victims identified as sites for romance-baiting fraud, Ponzi-style schemes, and attempted theft of digital-asset wallets. The network has also been connected to infrastructure used to move illicit proceeds across borders and to support large-scale money laundering tied to fraud proceeds extracted from victims in the United States. Reporting links the broader K99-associated ecosystem to coercive labor practices, physical confinement, and threats of violence against trafficking victims compelled to participate in scam operations. Known associated entities include K99 Culture and Media Co Ltd as well as linked companies such as Xing Tian Di Co Ltd and Nan Tian International Hotel Co Ltd, also known as Nan Hai. The group is best characterized as a transnational organized criminal network centered in Cambodia, with a dominant financial motivation and operational overlap with human-trafficking-enabled cyber-enabled fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.