Spanish Authorities Arrest GXC Team Leader in Takedown of Banking Fraud Network

Summary
Spanish authorities arrested the alleged GXC Team mastermind and six customers after raids disrupted a phishing-as-a-service operation using fake banking sites, Android malware and AI-generated voice calls to steal money.
Key points
- In May 2025, Spain’s Guardia Civil conducted six simultaneous raids and arrested the alleged mastermind, known as “GoogleXcoder,” along with six people who had bought the group’s tools.
- GXC Team sold phishing kits impersonating Spanish banks and international institutions, plus Android malware that intercepted SMS messages and bank one-time passwords.
- Its phishing pages harvested credentials and personal details; AI-generated calls impersonating banks were used to trick victims into sharing 2FA codes or taking other actions.
- Group-IB identified more than 288 phishing domains, nine Android malware variants and over 100 assets linked to the operators.
- Authorities seized devices containing phishing code, customer communications and financial records; stolen funds were recovered from digital platforms, and the group’s Telegram channels went dark.
- Spanish authorities attributed millions of euros in losses to the group; investigators are still analyzing forensic evidence.
Article Details
- Event Type
- Law-enforcement takedown of a phishing-as-a-service fraud operation
- Impact
- Spanish authorities attributed millions of euros in financial losses to GXC Team, although the exact amount remains under investigation. Customers of more than 30 financial institutions had credentials harvested. Group-IB identified over 288 phishing domains and nine Android malware variants. May 2025 raids led to the arrest of the alleged mastermind and six customers who had used the group's tools; authorities seized devices and recovered stolen funds.
MITRE ATT&CK
T1056.003 · Web Portal CaptureFake banking portals captured credentials and other information entered by victims.T1412The Android malware intercepted SMS messages, including banking one-time passwords.T1566.002 · Spearphishing LinkSmishing messages directed victims to fake banking portals through links.