{"id":84672,"date":"2021-02-09T11:51:40","date_gmt":"2021-02-09T19:51:40","guid":{"rendered":"https:\/\/www.theaegisalliance.com\/?p=84672"},"modified":"2026-09-01T05:23:13","modified_gmt":"2026-09-01T12:23:13","slug":"ukraine-u-admin-arrest","status":"publish","type":"post","link":"https:\/\/theaegisalliance.com\/fr\/2021\/02\/09\/arrestation-de-ladministration-ukrainienne\/","title":{"rendered":"Ukraine Arrested the Author of U-Admin, a Phishing-as-a-Service Kit Used Against Banks in 11 Countries"},"content":{"rendered":"<figure id=\"attachment_84838\" aria-describedby=\"caption-attachment-84838\" style=\"width: 1000px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-84838\" src=\"https:\/\/theaegisalliance.com\/wp-content\/uploads\/Ukrainian-Police-Arrest-Author-of-Worlds-Largest-Phishing-Service-U-Admin.jpg\" alt=\"Ukrainian officials with a suspect and seized computer gear in the U-Admin phishing kit case\" width=\"1000\" height=\"500\" \/><figcaption id=\"caption-attachment-84838\" class=\"wp-caption-text\">Computer gear, cellphones, and hard drives were seized as part of five authorized searches during the operation.<\/figcaption><\/figure>\n<p><strong>TERNOPIL REGION, UKRAINE \u2014<\/strong> Ukrainian cyber police, working with the FBI and Australian Federal Police, arrested a 39-year-old man they say wrote U-Admin \u2014 also sold as Universal Admin and uPanel \u2014 a phishing-as-a-service kit that had been running since about 2016. The suspect used the handle Kaktys on crime forums. Five searches pulled computers, phones, and drives. Officials said the kit had been used against financial institutions in 11 countries. In Australia, authorities attributed more than 50 percent of 2019 phishing attacks to U-Admin and described hundreds of SMS campaigns that hit nearly every adult in the country several times.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2021\/02\/arrest-raids-tied-to-u-admin-phishing-kit\/\" target=\"_blank\" rel=\"noopener\">Brian Krebs<\/a> broke the technical picture. U-Admin was not a lone HTML page. It was a control panel with a phishing-page generator, a victim tracker, mule management, and a web-inject module that could prompt a target for a two-factor code. Operators bought branded pages that mimicked banks and social networks. Some paired the kit with malware such as Qakbot so a stolen session could move money. Hundreds of customers were identified. The author faced up to six years if convicted under Ukrainian law.<\/p>\n<div class=\"epyt-video-wrapper\">\n<div  style=\"display: block; margin: 0px auto;\"  id=\"_ytid_28765\"  width=\"480\" height=\"270\"  data-origwidth=\"480\" data-origheight=\"270\" data-facadesrc=\"https:\/\/www.youtube.com\/embed\/kSgkSn3MzyM?enablejsapi=1&#038;origin=https:\/\/theaegisalliance.com&#038;autoplay=0&#038;cc_load_policy=0&#038;cc_lang_pref=&#038;iv_load_policy=1&#038;loop=0&#038;rel=0&#038;fs=1&#038;playsinline=0&#038;autohide=2&#038;theme=dark&#038;color=red&#038;controls=1&#038;disablekb=0&#038;\" class=\"__youtube_prefs__ epyt-facade epyt-is-override  no-lazyload\" data-epautoplay=\"1\" ><img decoding=\"async\" data-spai-excluded=\"true\" class=\"epyt-facade-poster skip-lazy\" loading=\"lazy\"  alt=\"&quot;Phishing as a Service PhaaS - How Criminals Buy Them&quot;\"  src=\"https:\/\/i.ytimg.com\/vi\/kSgkSn3MzyM\/maxresdefault.jpg\"  \/><button class=\"epyt-facade-play\" aria-label=\"Play\"><svg data-no-lazy=\"1\" height=\"100%\" version=\"1.1\" viewBox=\"0 0 68 48\" width=\"100%\"><path class=\"ytp-large-play-button-bg\" d=\"M66.52,7.74c-0.78-2.93-2.49-5.41-5.42-6.19C55.79,.13,34,0,34,0S12.21,.13,6.9,1.55 C3.97,2.33,2.27,4.81,1.48,7.74C0.06,13.05,0,24,0,24s0.06,10.95,1.48,16.26c0.78,2.93,2.49,5.41,5.42,6.19 C12.21,47.87,34,48,34,48s21.79-0.13,27.1-1.55c2.93-0.78,4.64-3.26,5.42-6.19C67.94,34.95,68,24,68,24S67.94,13.05,66.52,7.74z\" fill=\"#f00\"><\/path><path d=\"M 45,24 27,14 27,34\" fill=\"#fff\"><\/path><\/svg><\/button><\/div>\n<\/div>\n<h2>Phishing kits do not retire when one author is cuffed<\/h2>\n<p>After the arrest, U-Admin customers did what crime-forum users do: they asked whether the panel was burned and whether the SQL injection bug Krebs and others had flagged would let cops read their victim databases. The Australian Federal Police&rsquo;s message was that continued use was a risk. The kit&rsquo;s persistence is the point. Phishing-as-a-service is a product line. You arrest a developer in Ternopil and the next panel is forked by the weekend.<\/p>\n<p>The AEGIS Alliance will not pretend one raid ended SMS phishing. We will say this is what international cooperation looks like when it actually produces a body in a chair instead of a press release about \u00ab\u00a0awareness.\u00a0\u00bb Ukraine&rsquo;s cyber police have a record of these takedowns. The United States and Australia supplied the victim data. The question that remains, as it always does, is whether the customers \u2014 the people who bought the pages and ran the SMS blasts \u2014 ever saw a courtroom.<\/p>\n<p>Related from The AEGIS Alliance: <a href=\"https:\/\/theaegisalliance.com\/2017\/12\/16\/ajit-varadaraj-pai-fcc-dox-doxed-hack-hacked-leaks-anonymous\/\">the Ajit Pai leak file<\/a>, <a href=\"https:\/\/theaegisalliance.com\/2024\/08\/22\/hardware-backdoor-found-in-rfid-cards-used-in-offices-and-hotels-all-over-the-world\/\">the RFID card backdoor<\/a>, <a href=\"https:\/\/theaegisalliance.com\/2024\/12\/30\/chinese-hackers-remotely-accessed-workstations-and-documents-in-a-major-cyber-incident-u-s-treasury-says\/\">the Treasury workstation breach<\/a>, and more <a href=\"https:\/\/theaegisalliance.com\/category\/news\/hacker-news\/\">Hacker News<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ukrainian police, working with the United States and Australia, arrested the 39-year-old author of U-Admin, a phishing-as-a-service kit used against banks and other targets in 11 countries. Australia said more than half of its 2019 phishing attacks ran on the panel.<\/p>\n","protected":false},"author":1,"featured_media":84838,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[196370,22,23,21,204522,204504],"tags":[195845,191867,192022,3674,205552],"class_list":["post-84672","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crime-news","category-hacker-news","category-international-news","category-news","category-other-videos","category-videos","tag-crime-news","tag-cybersecurity","tag-hacker-news","tag-hackers","tag-ukraine"],"jetpack_featured_media_url":"https:\/\/theaegisalliance.com\/wp-content\/uploads\/Ukrainian-Police-Arrest-Author-of-Worlds-Largest-Phishing-Service-U-Admin.jpg","_links":{"self":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/84672","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/comments?post=84672"}],"version-history":[{"count":5,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/84672\/revisions"}],"predecessor-version":[{"id":1199484,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/84672\/revisions\/1199484"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/media\/84838"}],"wp:attachment":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/media?parent=84672"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/categories?post=84672"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/tags?post=84672"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}