Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors LabHost

Description

LabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for real-time campaign management and SMS lures. LabHost's phishing campaigns have similarities to Frappo campaigns, but they operate separately and offer different subscription packages.

AI Analysis

· 1 week ago

Executive Summary

LabHost is a threat actor group targeting Canadian banks through Phishing-as-a-Service campaigns, leveraging tools such as LabRat and LabSend for real-time attack orchestration. While their tactics resemble those of the Frappo group, LabHost operates independently and offers distinct subscription-based services. Their campaigns are specifically tailored to the financial sector, suggesting a focus on credential theft and fraud.

Goals & Targeting

LabHost's primary objective appears to be financial gain through fraud and credential theft, as evidenced by their focus on banks. Their targeting of the Canadian financial sector suggests an exploitation of regulatory environments, potential vulnerabilities, or the high value of financial data in this region. The use of subscription-based phishing services indicates a long-term monetization strategy, targeting organizations with resources to pay for such services. Their campaigns suggest a preference for sectors with access to sensitive data, which can be exploited for ongoing financial or strategic advantages.

Enhanced Description

LabHost has emerged as a specialized threat actor targeting Canadian financial institutions through a Phishing-as-a-Service model, which enables automated, scalable phishing operations. The group employs tools like LabRat and LabSend, which facilitate real-time campaign management and SMS-based luring techniques. These methods suggest a structured approach to phishing, with the ability to rapidly deploy and adapt attacks. Although their campaign patterns bear similarities to those of the Frappo group, LabHost operates as a distinct entity and distinguishes itself through unique subscription models. The operational model implies an organized structure that prioritizes efficiency and monetization through subscription-based access to their phishing services. The group's focus on Canadian banks indicates a strategic interest in the financial sector, leveraging the high value of credentials and financial data associated with such targets.

Key Capabilities

  • Phishing-as-a-Service (PaaS) infrastructure with automated campaign deployment
  • Real-time campaign orchestration using LabRat and LabSend tools
  • SMS-based phishing lures for targeted victim engagement
  • Custom phishing tooling tailored for financial institutions

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Impact

ATT&CK Techniques

T1192.003 - Phishing - Spearphishing via link
T1204.002 - User Execution - Malicious File
T1566.001 - Phishing - Social Engineering
T1102.001 - User Input - Input Manipulation

Software / Tooling

LabRat
LabSend

Campaigns & Victims

LabHost's campaigns exhibit a structured operational tempo, with a focus on the Canadian financial sector. Their use of subscription-based services suggests an ongoing, scalable model targeting organizations with the capacity to pay for phishing infrastructure. The group's reliance on SMS lures and customized tools indicates a focus on bypassing traditional email defenses. While no specific campaigns are linked in available data, their operational methods align with known PaaS models, implying a preference for low-cost, high-impact targeting. Their campaigns may be part of a larger ecosystem of cybercriminal services.

IOC Patterns

  • Spear-phishing via SMS with lures targeting financial institutions
  • Use of LabRat and LabSend for campaign control
  • Malicious URLs or payloads embedded in phishing messages
  • Phishing campaigns with subscription-based access patterns

Recommended Actions

  • Implement multi-factor authentication (MFA) for all banking systems and user accounts
  • Enhance employee training on phishing and social engineering detection, with a focus on SMS-based threats
  • Deploy advanced threat intelligence platforms to detect LabHost infrastructure and indicators
  • Monitor for unusual network activity or login patterns indicative of credential theft
  • Conduct regular penetration testing to identify vulnerabilities exploitable by PaaS models

Suggested Tags

APT
phishing
financial-sector
Phishing-as-a-Service

Confidence Assessment

The confidence level in the provided data is moderate, as the threat actor's motivations, sophistication, and full operational scope are not explicitly detailed. Gaps include unconfirmed links to specific MITRE ATT&CK techniques, unverified first/last seen dates, and limited information on attribution beyond the group's own tools and campaign similarities to Frappo. Further intelligence collection is needed to confirm capabilities and expand the threat profile.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Backdoor / C2
APT
phishing
financial-sector
Phishing-as-a-Service

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.