Spanish law enforcement successfully dismantled the GXC Team cybercrime syndicate and arrested its 25-year-old Brazilian leader, known as 'GoogleXcoder.' The Guardia Civil led a coordinated operation across multiple Spanish cities, including Cantabria, Valladolid, Zaragoza, Barcelona, Palma de Mallorca, San Fernando, and La Línea de la Concepción, resulting in the seizure of electronic devices, phishing kit source code, client communications, and financial records. GXC Team operated as a crime-as-a-service platform, providing AI-powered phishing kits, Android malware, and voice-scam tools through Telegram and Russian-speaking hacker forums. The group was a major supplier of credential theft tools, particularly in Spain, but also targeted banks, transport, and e-commerce entities in Slovakia, the UK, the US, and Brazil. Their phishing kits replicated the websites of numerous Spanish and international institutions, powering at least 250 phishing sites. The group developed at least nine Android malware strains capable of intercepting SMS and one-time passwords, facilitating account hijacking and fraudulent transactions. GXC Team also offered technical support and campaign customization, positioning itself as a professional and high-yielding crime platform. In late 2023, the group introduced an AI-powered tool for generating fraudulent invoices, which was used in wire fraud and business email compromise (BEC) schemes. This tool, named 'Business Invoice Swapper,' was available for rent starting at $2,000 per week or a one-time fee of $15,000, and required operators to input compromised email credentials and banking information for spoofing. The group promoted its products and services via Telegram channels, including one provocatively named 'Steal everything from grandmothers.' The operation led to the recovery of stolen cryptocurrency and the shutdown of these Telegram channels. According to the FBI, BEC scams like those enabled by GXC Team's tools have caused average losses of over $120,000 per incident, with total damages exceeding $2.4 billion. The dismantling of GXC Team is considered a significant blow to the cybercrime ecosystem in the Spanish-speaking world, disrupting a major supplier of advanced phishing and credential theft tools. The investigation was supported by threat intelligence from firms such as Resecurity and Group-IB, who had been tracking the group's activities and tool development. The arrest of 'GoogleXcoder' and the seizure of infrastructure are expected to have a substantial impact on the availability of crimeware in the region. Law enforcement continues to analyze the seized devices for further leads and to identify additional victims and collaborators. The case highlights the increasing sophistication of cybercrime groups leveraging AI and offering crimeware as a service to a global clientele.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Spanish law enforcement's takedown of GXC Team and the arrest of its alleged leader were publicly reported, describing the group as one of the most active cybercrime networks and highlighting its use of AI-enabled scam tools. Multiple outlets covered the announcement as the first public disclosure of the operation's results.
On May 20, 2025, the Spanish Guardia Civil carried out an operation that dismantled the GXC Team network and arrested its alleged leader, a 25-year-old Brazilian known as GoogleXcoder. Authorities also seized digital evidence and recovered stolen funds during the action.
The Guardia Civil opened an investigation into the GXC Team cybercrime network, with support from Group-IB. Investigators ultimately linked the group to more than 250 fraudulent websites and nine malware variants used in large-scale fraud schemes.
Spanish authorities said GXC Team had been active since at least 2023, offering crime-as-a-service tools including phishing kits, Android malware, and scam infrastructure to other criminals. The group targeted banks, transportation companies, and online shops in multiple countries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcesecurityaffairs.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.