LabHost is a phishing-as-a-service (PhaaS) cybercrime platform that provided phishing tools and services for a fee. Reporting in the provided content states that it hosted more than 40,000 phishing domains and had roughly 10,000 users. Law enforcement dismantled the platform in April 2024 in an international operation involving 19 countries, raiding 70 locations, arresting 37 individuals, and seizing infrastructure. The FBI later published a list of 42,000 domains recovered from LabHost servers. The content also states that investigators found more than one million stolen user credentials and nearly 500,000 compromised credit cards on its servers. Based on the provided material, LabHost was used to support large-scale phishing operations and credential and payment-card theft. No additional technical malware-family behaviors or host-based indicators are directly provided beyond its role as a phishing infrastructure and service platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-as-a-service platform associated with large-scale domain infrastructure used for credential theft.
Phishing-as-a-service platform that provided infrastructure for large-scale credential and credit card theft, with over one million stolen credentials and nearly 500,000 compromised credit cards found on its servers.
Phishing-as-a-Service platform used by cybercriminals to conduct large-scale phishing attacks, offering customizable kits and real-time victim monitoring.
Phishing-as-a-service platform providing phishing tools and infrastructure to cybercriminals, facilitating credential theft and fraud.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.