Spanish Authorities Arrest GXC Team Leader in Takedown of Banking Fraud Network

· Original article ↗

Summary

Spanish authorities arrested the alleged GXC Team mastermind and six customers after raids disrupted a phishing-as-a-service operation using fake banking sites, Android malware and AI-generated voice calls to steal money.

Key points

  • In May 2025, Spain’s Guardia Civil conducted six simultaneous raids and arrested the alleged mastermind, known as “GoogleXcoder,” along with six people who had bought the group’s tools.
  • GXC Team sold phishing kits impersonating Spanish banks and international institutions, plus Android malware that intercepted SMS messages and bank one-time passwords.
  • Its phishing pages harvested credentials and personal details; AI-generated calls impersonating banks were used to trick victims into sharing 2FA codes or taking other actions.
  • Group-IB identified more than 288 phishing domains, nine Android malware variants and over 100 assets linked to the operators.
  • Authorities seized devices containing phishing code, customer communications and financial records; stolen funds were recovered from digital platforms, and the group’s Telegram channels went dark.
  • Spanish authorities attributed millions of euros in losses to the group; investigators are still analyzing forensic evidence.

Article Details

Event Type
Law-enforcement takedown of a phishing-as-a-service fraud operation
Impact
Spanish authorities attributed millions of euros in financial losses to GXC Team, although the exact amount remains under investigation. Customers of more than 30 financial institutions had credentials harvested. Group-IB identified over 288 phishing domains and nine Android malware variants. May 2025 raids led to the arrest of the alleged mastermind and six customers who had used the group's tools; authorities seized devices and recovered stolen funds.

MITRE ATT&CK

People

Threat Actors

Vendors

Countries

Industries

Related Articles