INTERPOL said Operation Lyrebird led to the identification and arrest in Morocco of a suspected cybercriminal known as Dr HeX after a two-year investigation supported by Group-IB. Moroccan authorities apprehended the suspect following coordination between INTERPOL’s Cybercrime Directorate and the INTERPOL National Central Bureau in Rabat, and the individual remains under investigation.
Group-IB said its inquiry began with a phishing kit impersonating a major French bank, which yielded an email address and nickname that investigators used to connect the suspect to a wider malicious infrastructure. The company linked the actor, described as active since at least 2009, to phishing, website defacements, malware development, fraud, carding, attacks on French telecommunications firms, major banks, and multinational companies, as well as more than 130 website defacements and underground forum activity involving malware trading.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In May, Moroccan police arrested the Moroccan suspect known as Dr HeX based on cybercrime intelligence provided by Group-IB during INTERPOL's Operation Lyrebird. INTERPOL's Cybercrime Directorate coordinated with Moroccan authorities through the National Central Bureau in Rabat.
Group-IB attributed over 130 website defacements to Dr HeX over the period from 2009 to 2018. This historical activity formed part of the broader attribution case against the suspect.
Group-IB assessed that the suspect it dubbed Dr HeX had been active since at least 2009, engaging in phishing, fraud, carding, malware development, and other cybercrime. The company also linked the actor to a long-running pattern of malicious activity affecting thousands of victims.
Group-IB said its investigation attributed phishing, malware, and intrusion activity by Dr HeX to a French corporation, French telecommunications companies, major French banks, and several multinational corporations. It also said the suspect attempted to steal banking card data from the French corporation.
Group-IB said its investigation began after analysts extracted a phishing kit impersonating a large French bank and used artifacts in the kit to trace the actor's infrastructure and online identities. The investigation ultimately identified multiple email addresses, nicknames, and social media or communication accounts tied to the suspect.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
group-ib.com
Open sourcetherecord.media
Open sourceinterpol.int
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.