The U.S. Department of Justice said it seized 39 domains and associated servers linked to a Pakistan-based cybercrime marketplace network allegedly operated by Saim Raza, also known as HeartSender. Prosecutors said the sites sold phishing kits, scam pages, email extractors, and other fraud-enabling tools to transnational organized crime groups, with the tooling used largely in business email compromise and credential-theft schemes that caused more than $3 million in victim losses. The takedown was carried out with the Dutch National Police as part of an international disruption effort targeting infrastructure that had allegedly supported criminal activity since at least 2020.
Prior threat intelligence had linked the same ecosystem to the Manipulaters Team, a Pakistani group accused of marketing spam and malware tooling under the Saim Raza persona and advertising products as FUD to suggest evasion of antivirus and anti-spam defenses. Researchers identified recurring infrastructure patterns across the network, including domains using nameservers from blazingfast.io and cloudflare.com, registrations through Internet Domain Service BS Corp., hosting on Netsolutions and Cloudflare, and naming conventions featuring terms such as fud, tool, page, sender, and spam. Authorities also said the marketplaces offered training materials, including YouTube tutorials, lowering the barrier for less technically skilled fraud actors.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
The U.S. Attorney's Office for the Southern District of Texas announced the seizure action, saying the marketplaces supplied phishing and business-email-compromise tooling used against U.S. victims and linked to more than $3 million in losses.
On January 29, 2025, U.S. authorities, coordinated with the Dutch National Police, seized 39 domains and associated servers tied to a Pakistan-based cybercrime marketplace network allegedly operated by Saim Raza.
Silent Push published analysis linking the Manipulaters Team, believed to operate behind the Saim Raza persona, to phishing- and spam-tool sales infrastructure and released a list of attributed domains and indicators.
According to a DOJ affidavit, Saim Raza's cybercrime marketplace network had been used since at least 2020 to sell phishing kits, scam pages, email extractors, and related fraud-enabling tools to criminal groups.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 73 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourcesilentpush.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.