Ukraine Arrested the Author of U-Admin, a Phishing-as-a-Service Kit Used Against Banks in 11 Countries

TERNOPIL REGION, UKRAINE — Ukrainian cyber police, working with the FBI and Australian Federal Police, arrested a 39-year-old man they say wrote U-Admin — also sold as Universal Admin and uPanel — a phishing-as-a-service kit that had been running since about 2016. The suspect used the handle Kaktys on crime forums. Five searches pulled computers, phones, and drives. Officials said the kit had been used against financial institutions in 11 countries. In Australia, authorities attributed more than 50 percent of 2019 phishing attacks to U-Admin and described hundreds of SMS campaigns that hit nearly every adult in the country several times.
Brian Krebs broke the technical picture. U-Admin was not a lone HTML page. It was a control panel with a phishing-page generator, a victim tracker, mule management, and a web-inject module that could prompt a target for a two-factor code. Operators bought branded pages that mimicked banks and social networks. Some paired the kit with malware such as Qakbot so a stolen session could move money. Hundreds of customers were identified. The author faced up to six years if convicted under Ukrainian law.

Phishing kits do not retire when one author is cuffed
After the arrest, U-Admin customers did what crime-forum users do: they asked whether the panel was burned and whether the SQL injection bug Krebs and others had flagged would let cops read their victim databases. The Australian Federal Police’s message was that continued use was a risk. The kit’s persistence is the point. Phishing-as-a-service is a product line. You arrest a developer in Ternopil and the next panel is forked by the weekend.
The AEGIS Alliance will not pretend one raid ended SMS phishing. We will say this is what international cooperation looks like when it actually produces a body in a chair instead of a press release about “awareness.” Ukraine’s cyber police have a record of these takedowns. The United States and Australia supplied the victim data. The question that remains, as it always does, is whether the customers — the people who bought the pages and ran the SMS blasts — ever saw a courtroom.
Related from The AEGIS Alliance: the Ajit Pai leak file, the RFID card backdoor, the Treasury workstation breach, and more Hacker News.









