Tajin Group's Phishing and Global Money Laundering Network
Score: 7/10

Tajin Group's Phishing and Global Money Laundering Network

Tajin Group operates a sophisticated phishing and money laundering network targeting global financial institutions and Chinese citizens using Telegram-based guarantee marketplaces and anonymous virtual assets.

Executive Summary

Tajin Group (踏金集团) is a prominent Chinese-speaking threat group specializing in phishing, payment card theft, and large-scale money laundering. Operating primarily on Telegram-based guarantee marketplaces like Dabai and Xinbi Guarantee, the group functions as a high-volume vendor, staking significant cryptocurrency deposits (e.g., 208,848 USDT) to establish credibility. Their operations are global, targeting citizens and financial institutions across dozens of countries including China, the UK, South Africa, and the UAE.

Technically, Tajin Group leverages third-party payment gateways such as CCAvenue UAE, Geidea, and N-Genius to process illicit transactions. They exhibit high operational security (OPSEC) by using the Fragment Market to acquire anonymous virtual phone numbers and collectible Telegram usernames as NFTs, decoupling their identities from physical SIM cards. Their tactics include 'ghost-tapping,' NFC relay techniques, and exploiting 2D/3D payment gateways to cash out stolen credit card data (CVVs).

The group's ability to adapt to banking security protocols—such as identifying BINs that bypass 3D Secure (3DS) authentication—and their use of diverse cash-out methods (e.g., luxury jewelry and eGift cards) poses a significant threat to the global payment industry. Their model is likely to be replicated by other threat actors within the growing Chinese-language cybercriminal ecosystem.

Key Details

Threat Name

Tajin Group

Affects

—

Adversary

Tajin Group Other Adversaries and Aliases: Dream of Red Chamber Global Access

MITRE Techniques

—

Malware/Tools

Dream of Red Chamber Global Access

Report Score

7out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance2
Enterprise Relevance7
Clarity & Structure9
Technical Depth7

Sources