Crime NewsNouvelles du HackerNouvelles internationalesNewsAutres vidéosVideos

Ukraine, the FBI, and Australia Arrested the U-Admin Phishing-Kit Author, and the Phishing-as-a-Service Market Kept Selling

TERNOPIL REGION, UKRAINE — Ukrainian cyber police, working with the FBI and the Australian Federal Police, arrested a 39-year-old man they identified as the author of U-Admin, a phishing kit also sold as Universal Admin and uPanel. The suspect posted on crime forums under the handle Kaktys. Officers ran five court-authorized searches in the Ternopil region and took computers, phones, and hard drives. Prosecutors said the panel had been aimed at banks and other financial targets in 11 countries: Australia, Spain, the United States, Italy, Chile, the Netherlands, Mexico, France, Switzerland, Germany, and the United Kingdom. If convicted under Ukrainian law for creating and distributing the malware and for breaking into computer systems, he faced up to six years.

Australia is where the kit stopped being a forum rumor and became a national statistic. Authorities there attributed more than half of all phishing attacks in 2019 to U-Admin and described hundreds of SMS campaigns that reached nearly every adult in the country more than once. A text message that looks like a bank, a parcel, or a toll bill is a cheap way to move a person onto a fake page. U-Admin industrialized the page. The Ukrainian prosecutor general’s office and the cyber police said the author had not only sold the software through a dark-web storefront but had stayed on the line as technical support while attacks were running. More than 200 active buyers were identified. A developer with a support contract is not a kid who uploaded one HTML file. He is a vendor.

Brian Krebs published the mechanical picture as the raids became public in February 2021. U-Admin was a control panel. It generated the phishing pages, tracked the victims who typed into them, managed the money mules who would move what was stolen, and included a web-inject module that could interrupt a session and ask the target for a two-factor code. Operators bought branded templates that copied banks and social networks. Some customers paired the panel with malware such as Qakbot so that a stolen browser session could be used to move money without waiting for the victim to type a password a second time. The product had been on the market since about 2016. Five years is a long life for a criminal web app, and it is long enough for the customers to outnumber the author by orders of magnitude.

The customers asked whether the panel was burned

The arrest did not land in silence on the forums where the kit was sold. Customers did what customers of a compromised vendor do. They asked whether the panel was burned, and they asked about a SQL injection flaw that researchers, including a detailed public teardown hosted by FR3D, had already documented. A bug that lets an outsider read a database is, in legitimate software, a patch. In a phishing panel it is a question about whether police can see every victim the customers have collected, every mule account, and every campaign. The Australian Federal Police’s public line was the practical one: people still using the kit were taking a risk that the infrastructure was no longer theirs. Some operators would abandon it. Some would keep running pages until a bank or a phone carrier blocked the domain. The author in a chair in Ternopil could not remotely revoke every copy that had already been sold.

That is the structural fact of phishing-as-a-service, and it is why a single arrest is not a retirement. The kit is a product line. Source code, templates, and customer habits fork. A competitor who watched U-Admin’s customers panic had a sales pitch ready by the next weekend: same pages, different host, no Ukrainian warrant. The United States and Australia had supplied victim data that made the Ternopil case real, which is what international cooperation looks like when it produces searches instead of an awareness poster. The open question, the one the arrest announcement could not answer, was whether the 200 buyers would ever sit in a courtroom of their own. Selling the panel is one crime. Running a thousand SMS blasts against a credit union is another, and it is committed by the customer.

The product line outlived the author

The years after the Ternopil arrest read as a catalog of the same business with new names. In April 2024, police from 19 countries, coordinated by Europol and led by the London Metropolitan Police, disrupted LabHost, a phishing-as-a-service site on the open web that charged a monthly fee averaging $249. Officers searched 70 addresses and arrested 37 people, including, in the United Kingdom, the alleged original developer. Europol tied at least 40,000 phishing domains to the service and put the user base at about 10,000. Australian police took down 207 servers aimed at more than 94,000 people there. British detectives said just under 70,000 people in the United Kingdom had typed details into LabHost pages. LabHost was U-Admin’s idea at subscription scale. Arresting the developer does not unsend the links.

A year later the same idea was being sold by a student who had not needed a dark-web brand at all. On July 23, 2025, Southwark Crown Court sentenced Ollie Holman, 21, of Eastcote in northwest London, to seven years and a Serious Crime Prevention Order. He had pleaded guilty to seven counts. The City of London Police and the Crown Prosecution Service said he created and sold 1,052 phishing kits, with scripts that captured logins and card numbers, and that he advised buyers over Telegram. The kits targeted 69 financial institutions, companies, and charities across 24 countries. Prosecutors linked the fraud losses to about £100 million. One kit copied a charity donation page so that a person trying to give money handed the card to the criminal instead. Sarah Jennings of the CPS said Holman « acted with greed and profited handsomely from this illegal enterprise, funding his own lavish lifestyle at the expense of countless individuals and businesses. » Detective Sergeant Ben Hurley said Holman had enabled mass fraud and had given no thought to the victims. Holman was studying electronic and computer engineering at the University of Kent in Canterbury. Police arrested him in his dormitory room in October 2023 after a tip from the intelligence firm WMC Global, and he had laundered proceeds through cryptocurrency wallets. A seven-year sentence is what a phishing-kit author looks like when the case is finished in a London courtroom. The Ukrainian announcement in 2021 stopped at « up to six years » and a suspect in custody. The AEGIS Alliance has not found a public judgment that names Kaktys, states a conviction, and records a final sentence. An arrest without a published verdict is not the same document as Holman’s.

The subscription panels kept coming. On March 4, 2026, Europol’s European Cybercrime Centre and police in Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom seized 330 domains used by Tycoon2FA, a phishing-as-a-service platform built to steal logins and to sit in the middle of multifactor authentication so that a one-time code typed by the victim is captured and replayed. CrowdStrike, writing later that month, called the seizure a real disruption of a widely used tool and also warned that this class of adversary reconstitutes. The company noted that, as of its March account, additional action against the individuals behind Tycoon2FA had not yet been reported, and that the same style of platform had already survived a September 2025 strike on a competitor known as RaccoonO365. In August 2026, researchers at Trend said intelligence they had shared with Europol and Interpol informed arrests of two operators tied to Tycoon2FA. A domain seizure in March and an arrest announcement in August can both be true, and neither one retires the copies already in customers’ hands. The parallel to U-Admin is exact. Police can cuff a developer in Ternopil, or seize 330 domains in Europe, and the next panel is a configuration file away.

What the 2021 searches accomplished is narrower than a victory lap, and worth saying without inflation. A man accused of running a panel that dominated Australian SMS phishing in 2019 was identified and charged because the FBI and the Australian Federal Police handed victim data to Ukrainian investigators instead of stopping at a warning. The pages mimicked banks. The inject module asked for the second factor banks had told customers would save them. The customers, more than 200 of them, were the distribution network. Unless those customers were charged where they operated, the texts did not end in Ternopil. U-Admin’s author, if the identification holds, built a business in which inexperience was not a barrier. LabHost priced that business by the month. Holman priced it by the kit and drew seven years. Tycoon2FA priced it as a way through the text-message code. The Ternopil arrest was early proof that a vendor can be found. It was not proof that the store stays closed.

Related from The AEGIS Alliance: the Ajit Pai leak file, the RFID card backdoor, the Treasury workstation breach, the IRS-impostor phishing surge, the global phishing-service arrest tied to Microsoft 365, Google’s takedown of a phone-traffic shadow network, and more Nouvelles du Hacker.

Kyle James Lee
Majorité propriétaire de l'alliance de l'égide. J'ai étudié à l'université pour les arts médiatiques, le développement de jeux. Les talents comprennent écrivain/rédacteur d'articles, conception graphique, photoshop, conception et développement Web, Production Video, médias sociaux et commerce électronique.

Articles similaires

Bouton retour en haut de la page