Uptime Hamster: 10d 19h 56mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza PayTool

PayTool

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Ver en IntelTracker → APTTrail →
PayTool refers to a dynamic payment collection system and fraud framework that first emerged around the fall of 2021, continuously evolving its infrastructure and operational model. It is primarily utilized by Chinese-speaking threat actors, as evidenced by linguistic artifacts in code, typical operating hours, and historical ties to similar scam operations. The primary motivation behind PayTool is large-scale financial gain through sophisticated impersonation scams. This framework distinguishes itself by specializing in mimicking legitimate government services and trusted national brands, particularly in Canada, to harvest sensitive financial and personal information. Its defining characteristic is its high adaptability, marked by rapid domain rotation, frequent registration of new domains to bypass blacklisting, and a continuous expansion of its targeting from initial traffic violation scams to broader themes like tax refunds, airline bookings, and postal delivery alerts. It operates
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
7
Actualizado
Wed, 11 Fe