Tajin Group is a Chinese-speaking cybercriminal group specializing in phishing, payment-card theft, carding, financial fraud, and money laundering. It has operated as a vendor on Chinese-language, Telegram-based guarantee marketplaces, transitioning from Dabai Guarantee to Xinbi Guarantee in 2026. The group primarily targets mainland Chinese citizens and Chinese banks, while sourcing and testing payment cards and payment-processing channels across multiple countries for cross-border fraud and cash-out activity. Tajin Group has advertised fraudulent payment processing through 2D and 3D payment gateways, card-to-cryptocurrency conversion, electronic gift-card laundering, contactless payment-card abuse, ATM cash-out methods, and payment-card channels supporting major international and Chinese card networks. Its operators have also sought partnerships providing access to payment gateways, compromised payment-card data, remote-control services, and related fraud infrastructure. The group has used anonymous virtual phone numbers and traded Telegram usernames to support operational anonymity. Its dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A third-party vendor on Chinese-language Telegram guarantee marketplaces that conducts phishing, payment-card theft/carding, payment fraud, and money laundering. It tested payment cards from multiple countries on CCAvenue and Geidea, sought payment channels and gateways supporting major card schemes, and moved from Dabai Guarantee to Xinbi Guarantee. Its operators also acquired Telegram usernames and anonymous virtual numbers to improve operational anonymity.
A Chinese-speaking financially motivated cybercriminal group conducting phishing, payment-card theft and carding, unauthorized transactions, cash-out operations, and money laundering. It brokers and processes stolen card data through payment gateways, gift cards, and bank-transfer channels, and uses anonymous Telegram usernames and virtual numbers to improve operational security.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.