Malaysian law enforcement authorities, in collaboration with the Australian Federal Police and the US Federal Bureau of Investigation, have successfully dismantled BulletProofLink, a major phishing-as-a-service (PhaaS) and initial access broker (IAB) operation.


BulletProofLink, which had been active since 2015, provided tools and resources for conducting phishing attacks. These included login pages for popular services and a tool for bypassing multi-factor authentication. With over 8,000 clients, BulletProofLink generated significant profits, potentially making over 1.2 million Malaysian ringgit ($250,000) from their scams.

The operation was brought down through intelligence shared by the Australian Federal Police and the FBI, leading to the arrests of eight individuals, including the alleged mastermind and a software engineer. The cybersecurity firm Intel471 had previously warned about BulletProofLink's acquisition of the Evilginx2 source code, which could enable adversary-in-the-middle (AITM) phishing attacks. The lack of operational security by the group allowed cybersecurity vendors to uncover their real-world identities.

As part of the operation, authorities seized servers, computers, a cryptocurrency wallet, electronic devices, jewelry, and vehicles, including approximately $213,000 in cryptocurrency. The closure of BulletProofLink marks a significant victory against cybercriminals, as it was a key source for infiltrating corporate networks.


The successful dismantling of BulletProofLink has significant impacts in the fight against cybercrime. It disrupts a major phishing-as-a-service operation and removes a key source for infiltrating corporate networks. The collaboration between Malaysian law enforcement, the Australian Federal Police, and the FBI demonstrates the importance of international cooperation in combating cyber threats.

This operation also highlights the need for improved operational security by cybercriminals. The lack of proper security measures allowed cybersecurity vendors to uncover the identities of those involved. This serves as a reminder to cybercriminals that their actions are not anonymous and they can be held accountable for their crimes.

Moving forward, it is crucial for law enforcement agencies and cybersecurity firms to continue sharing intelligence and collaborating to dismantle similar operations. By doing so, we can better protect individuals, organizations, and critical infrastructure from the ever-evolving threat of cybercrime.