U.S. authorities extradited 26-year-old Algerian national Abdellah Belmili from Spain and charged him in the Western District of New York with conspiracy to commit bank fraud for allegedly operating the cybercrime marketplaces market0day.com and spoxy.us. Prosecutors said the platforms sold phishing kits targeting major U.S. financial institutions, compromised email server access, financial credentials, and bulk SMS services used in mass phishing campaigns, with transactions processed in Bitcoin. Investigators said undercover purchases in December 2020 included a JPMorgan Chase phishing kit and access to a compromised email server.
According to court allegations, Belmili, also known as "SPOX," "Spox," and Dila Belmili, created about 595 phishing kits and helped defraud multiple U.S. and U.K. financial institutions, affecting roughly 5,600 victims worldwide. Authorities linked him to the operation through embedded identifiers in phishing kit source code, social media and Google records, and Binance transaction data, and said about $900,000 moved through an account he controlled between January 2020 and January 2023. Prosecutors also alleged he secretly inserted backdoors into phishing kits sold to other criminals so he could continue harvesting victim data after the kits were resold; he is now in U.S. custody and faces up to 30 years in prison if convicted.

See the reporting duties and controls this puts on the clock.
9 events from the most recent confirmed update back to the earliest known activity.
U.S. authorities seized a cloud computing account linked to Cambodia-based Huione Guarantee, also known as Haowang Guarantee, which they said facilitated cybercrime, money laundering, and scam operations through Telegram channels and escrow services. The reference describes this as a separate enforcement action from the Belmili extradition case.
U.S. authorities extradited Abdellah Belmili from Spain to the United States and charged him in the Western District of New York with conspiracy to commit bank fraud over his alleged operation of Market0Day and Spoxy.
Authorities say the flow of approximately $900,000 in deposits tied to the alleged conspiracy continued through January 2023, marking the end of the period cited in court filings.
Prosecutors allege that Belmili later launched Spoxy, a marketplace offering bulk SMS services used for mass phishing and related campaigns.
According to the Justice Department, Abdellah Belmili administered the cybercrime marketplace Market0Day in late 2020, where phishing kits and other fraud-enabling tools were sold.
Prosecutors allege that approximately $900,000 in deposits flowed to an account controlled by Abdellah Belmili between January 2020 and January 2023 as part of the alleged fraud conspiracy tied to Market0Day and Spoxy.
After being extradited to the United States, Abdellah Belmili made an initial appearance in Buffalo and was detained pending further proceedings in the bank fraud conspiracy case.
In December 2020, investigators reportedly purchased a JPMorgan Chase phishing kit and access to a compromised email server from Market0Day as part of the investigation into Belmili's alleged operation.
The FBI began investigating Abdellah Belmili in September 2020 after receiving a tip from a confidential source about the alleged cybercrime operation tied to Market0Day and Spoxy.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcesecurityweek.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.