The FBI has released a list of 42,000 phishing domains connected to the LabHost cybercrime platform, which was dismantled in April 2024. These domains, registered between November 2021 and April 2024, are being shared to increase awareness and provide indicators of compromise for cybersecurity professionals.
## LabHost: A Major Phishing-as-a-Service Operation
LabHost was one of the largest global phishing-as-a-service (PhaaS) platforms, selling access to sophisticated phishing kits targeting U.S. and Canadian banks for $179-$300 monthly. The platform offered:
– Extensive customization options
– Advanced 2FA-bypassing mechanisms
– Automatic SMS-based victim interactions
– Real-time campaign management
Though launched in 2021, LabHost became a dominant player in late 2023, surpassing established competitors in popularity and attack volume. The platform reportedly stole over 1 million user credentials and nearly 500,000 credit card records before its takedown.
## Global Law Enforcement Takedown
In April 2024, a coordinated operation involving 19 countries led to LabHost’s dismantling. At the time, the platform had approximately 10,000 customers worldwide. The operation included:
– Simultaneous searches at 70 addresses
– Arrest of 37 individuals with suspected links to LabHost
## Value for Cybersecurity Defenders
While these domains are likely no longer active in malicious operations, they provide significant value for security professionals:
– Creating blocklists to prevent domain recycling in future attacks
– Retrospective log scanning to identify previously undetected breaches
– Analyzing domain patterns in PhaaS platforms
– Aiding attribution and intelligence correlation
– Providing realistic data for phishing detection model training
The FBI cautions that the list hasn’t been fully validated and may contain errors. Additionally, analysis may reveal further domains linked to the same infrastructure, suggesting the list may not be exhaustive.
