Cybersecurity researchers have uncovered the role of specialized service providers in enabling large-scale pig butchering scams, also known as romance baiting or investment fraud, particularly in Southeast Asia. These providers, such as the Penguin Account Store (also known as Heavenly Alliance and Overseas Alliance), operate under a crimeware-as-a-service (CaaS) model, supplying turnkey scam platforms, fraud kits, stolen identities, and infrastructure that dramatically lower the barrier to entry for criminal groups. The scam operations are often run from compounds in special economic zones, where victims of human trafficking are forced to conduct fraudulent activities under threat of violence, and the infrastructure is designed to facilitate rapid laundering of stolen funds and cryptocurrencies beyond the reach of law enforcement.
The industrialization of pig butchering-as-a-service (PBaaS) has transformed the landscape of online fraud, with ready-made applications and templates now available for purchase, enabling scalable and efficient scam operations. The Penguin group exemplifies this trend, providing comprehensive packages that allow even non-technical actors to launch sophisticated social engineering campaigns. This development has contributed to the proliferation of global fraud, with law enforcement agencies and organizations like INTERPOL highlighting the intersection of cybercrime and human trafficking in these operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The same research described parked and typosquatted domains that profile visitors and redirect residential users to scam or malware content while showing benign pages to VPN users. This highlighted a broader service-provider layer supporting large-scale online fraud operations.
Infoblox detailed a Chinese-speaking 'Pig Butchering-as-a-Service' ecosystem centered on Penguin Account Store, also known as Heavenly Alliance or Overseas Alliance. The report said the operation sells stolen data, pre-registered accounts, SIMs, scam-management software, and payment services through BCD Pay to industrialize romance-baiting and investment fraud.
Infoblox said an adversary-in-the-middle phishing campaign using the Evilginx toolkit began targeting at least 18 U.S. universities on April 12, 2025. The activity was tied to 67 domains, with newer 'Evilginx Pro' capabilities making detection more difficult.
Researchers reported that a massive gambling-oriented infrastructure comprising more than 328,000 domains and subdomains has been active since at least 2011. The network was described as potentially dual-use and possibly linked to nation-state interests, using techniques such as WordPress/PHP exploitation, dangling DNS, and expired cloud assets to distribute Android malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.