Xinbi Guarantee is a sanctioned transnational criminal organization operating a Chinese-language illicit marketplace that has supported Southeast Asian scam-center ecosystems. The platform functioned as an intermediary and escrow service for scam operators, money-laundering networks, cybercrime syndicates, and vendors of illicit goods and services. Its offerings included infrastructure for investment and romance fraud, cryptocurrency cash-out and laundering services, stolen personal data, forged identity documents, deepfake tooling, and recruitment services linked to trafficking into scam compounds. Xinbi Guarantee primarily settled marketplace transactions using cryptocurrency and expanded following enforcement pressure against competing guarantee marketplaces. U.S. authorities designated Xinbi Guarantee as a significant transnational criminal organization in September 2026 and seized associated infrastructure and digital assets; the United Kingdom had previously sanctioned it. Cambodia-based Anwen Technology Co., Ltd., developer of the XinbiPay/NewPay digital-wallet application, and Singapore-based SafeW Technology Co., Ltd., developer of the SafeW encrypted messaging application, were designated for materially supporting Xinbi Guarantee. The platform has reportedly been used by North Korean hackers and by entities associated with the Prince Group transnational criminal organization. Its primary activity was financially motivated facilitation of cyber-enabled fraud and laundering rather than a state-directed espionage operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a Chinese-language, Telegram-based criminal marketplace supporting pig-butchering romance scams, wire-fraud proceeds laundering, scam infrastructure procurement, and trafficking of workers to Southeast Asian scam compounds. U.S. authorities seized associated channels and cryptocurrency wallets, while sanctions and asset freezes disrupted its payment network.
Operates an escrow-backed illicit marketplace connecting scam-center operators and other transnational criminal syndicates with vendors of stolen personal data, forged identity documents, deepfake tools, cryptocurrency cash-out and money-laundering services. It primarily settles transactions in USDT on TRON and reportedly migrated coordination to SafeW and payments to XinbiPay/NewPay amid enforcement pressure.
A designated transnational criminal organization operating an illicit online marketplace that connects scam-center operators, money-laundering networks, cybercrime syndicates, and merchants providing financial and technological services. Its platform offers escrow services and facilitates cyber scams, financial fraud, money laundering, and movement of stolen funds.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.