LabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for real-time campaign management and SMS lures. LabHost's phishing campaigns have similarities to Frappo campaigns, but they operate separately and offer different subscription packages.
Executive Summary
LabHost is a threat actor group targeting Canadian banks through Phishing-as-a-Service campaigns, leveraging tools such as LabRat and LabSend for real-time attack orchestration. While their tactics resemble those of the Frappo group, LabHost operates independently and offers distinct subscription-based services. Their campaigns are specifically tailored to the financial sector, suggesting a focus on credential theft and fraud.
Goals & Targeting
LabHost's primary objective appears to be financial gain through fraud and credential theft, as evidenced by their focus on banks. Their targeting of the Canadian financial sector suggests an exploitation of regulatory environments, potential vulnerabilities, or the high value of financial data in this region. The use of subscription-based phishing services indicates a long-term monetization strategy, targeting organizations with resources to pay for such services. Their campaigns suggest a preference for sectors with access to sensitive data, which can be exploited for ongoing financial or strategic advantages.
Enhanced Description
LabHost has emerged as a specialized threat actor targeting Canadian financial institutions through a Phishing-as-a-Service model, which enables automated, scalable phishing operations. The group employs tools like LabRat and LabSend, which facilitate real-time campaign management and SMS-based luring techniques. These methods suggest a structured approach to phishing, with the ability to rapidly deploy and adapt attacks. Although their campaign patterns bear similarities to those of the Frappo group, LabHost operates as a distinct entity and distinguishes itself through unique subscription models. The operational model implies an organized structure that prioritizes efficiency and monetization through subscription-based access to their phishing services. The group's focus on Canadian banks indicates a strategic interest in the financial sector, leveraging the high value of credentials and financial data associated with such targets.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LabHost's campaigns exhibit a structured operational tempo, with a focus on the Canadian financial sector. Their use of subscription-based services suggests an ongoing, scalable model targeting organizations with the capacity to pay for phishing infrastructure. The group's reliance on SMS lures and customized tools indicates a focus on bypassing traditional email defenses. While no specific campaigns are linked in available data, their operational methods align with known PaaS models, implying a preference for low-cost, high-impact targeting. Their campaigns may be part of a larger ecosystem of cybercriminal services.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the provided data is moderate, as the threat actor's motivations, sophistication, and full operational scope are not explicitly detailed. Gaps include unconfirmed links to specific MITRE ATT&CK techniques, unverified first/last seen dates, and limited information on attribution beyond the group's own tools and campaign similarities to Frappo. Further intelligence collection is needed to confirm capabilities and expand the threat profile.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics