Spanish Authorities Dismantle Advanced AI Phishing Operation GoogleXcoder
Spanish authorities have successfully dismantled an AI-driven phishing network, leading to the arrest of the developer known as “GoogleXcoder.” This operation marks a significant advancement in combating banking credential theft within Spain.
Spanish authorities have successfully dismantled an AI-driven phishing network, leading to the arrest of the developer known as “GoogleXcoder.” This operation marks a significant advancement in combating banking credential theft within Spain.
Targeting of Financial and Government Institutions
Since 2023, Spain has experienced an increase in sophisticated phishing attacks. Criminal groups have been impersonating major banks and government agencies using fraudulent websites to acquire personal and banking information from victims. These attacks have resulted in the theft of millions of euros, prompting public concern and an investigation by the Civil Guard’s Cybercrime Department.
The investigation identified “GoogleXcoder,” a 25-year-old Brazilian developer residing in Spain, as a key figure in these activities. Operating under a Crime as a Service (CaaS) model, he provided phishing kits that enabled criminals to replicate websites of financial institutions and government agencies. These kits, which included customization and technical support, facilitated phishing attacks for users with varying levels of technical expertise.
Transactions and communications primarily occurred via the messaging app Telegram, where criminals paid substantial fees for access to these tools. A Telegram group explicitly named “Stealing Everything from Grandmas” indicates the audacity and organization of these operations.
Since 2023, Spain has experienced an increase in sophisticated phishing attacks.
Despite frequent relocations and the use of spoofed identities, authorities apprehended “GoogleXcoder” in San Vicente de la Barquera, Cantabria. During the arrest, law enforcement seized electronic devices containing phishing kits, personal accounts, and communications with other perpetrators.
Ongoing forensic analysis of the confiscated devices and cryptocurrency transactions is underway to map the network and identify additional users of the phishing services. The operation also involved raids across several Spanish cities, including Valladolid, Zaragoza, Barcelona, Palma de Mallorca, San Fernando, and La Línea de la Concepción, resulting in the recovery of more stolen assets and digital evidence.
This successful operation, supported by the Brazilian Federal Police and cybersecurity firm Group IB, underscores the importance of international collaboration in addressing cross-border cybercrime. Further arrests are anticipated as the investigation continues to dismantle the phishing network and identify its members.
For additional information, please contact the Central Operations Unit at 91 503 13 27.
Based on reporting by GBHackers.
