BulletProofLink is a phishing-as-a-service (PhaaS) operation active since at least 2018 that has been marketed under the aliases BulletProftLink and Anthrax. It provides turnkey phishing capability to multiple customer groups through one-off purchases and subscription models, offering phishing kits, brand-themed templates, hosted phishing pages, email templates, credential collection workflows, and customer support. The service has been associated with large-scale credential-harvesting campaigns and with lowering the barrier to entry for less technically capable cybercriminals. BulletProofLink has offered more than 100 phishing templates impersonating well-known brands and services, including Microsoft-themed lures and Outlook-style sign-in pages. Its operating model has supported both self-hosted deployments by customers and operator-hosted landing pages. The service has also advertised automated services, hosted infrastructure, and recurring delivery of captured credentials or logs to customers. Campaigns linked to BulletProofLink have used defense-evasion and phishing tradecraft such as large-scale unique URL generation through infinite subdomain abuse, brand impersonation, zero-point font obfuscation in HTML emails, and user-specific phishing links containing encoded victim information. Researchers also tied the operation to recurring credential-processing patterns and infrastructure used to receive submitted passwords from phishing pages. A notable aspect of the operation is a reported “double theft” model in which stolen credentials may be delivered to the paying customer while also being retained by the operator for resale or reuse. This indicates that BulletProofLink functions not only as an enablement platform for downstream phishing actors but also as a direct credential-theft enterprise. Its role is best understood as cybercriminal service provision centered on phishing, credential harvesting, and supporting initial access activity for other threat actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
162 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.