FBI Uncovers 42,000 Phishing Domains Tied to LabHost PhaaS Platform

These included major banks, government institutions, postal services, and online streaming platforms. The service was used by approximately 10,000 cybercriminals worldwide who paid monthly subscription fees ranging from $179 to $300. 42,000 Phishing Domains Disclosed by FBI “The platform enabled cyber criminals to impersonate more than 200 organizations, including major banks and government institutions, in an effort to collect personal information and banking credentials from unsuspecting victims worldwide,” the FBI stated in its report. The bureau obtained the domain names and creation dates directly from LabHost’s backend servers following the platform’s dismantling. What made LabHost particularly dangerous was its comprehensive suite of services. The platform offered infrastructure configuration, customized phishing page creation, adversary-in-the-middle proxy connections to bypass two-factor authentication, SMS smishing capabilities, and stolen credential management. A core feature called “LabRat” allowed criminals to monitor phishing attacks in real-time and intercept authentication codes. The scale of LabHost’s operation was staggering. According to the FBI, the platform’s infrastructure stored over one million user credentials and nearly 500,000 compromised credit cards, enabling financial theft, fraud schemes, and money laundering. These stolen credentials impacted over a million victims globally. LabHost was taken down in April 2024 following a year-long international investigation coordinated by Europol and involving law enforcement agencies from 19 countries. The operation resulted in 70 searches across the globe and 37 arrests, including four key LabHost operators in the United Kingdom. The FBI emphasized that while these domains are historical in nature and may not currently be active for malicious purposes, the list provides valuable insight for network defenders and cyber threat intelligence personnel on adversary tactics and techniques. “Historical research that identifies connections to any of these domains should prompt additional response and follow-up with the impacted user(s),” the FBI advised. The full list of domain names is available at the FBI’s Internet Crime Complaint Center website. Organizations that identify activity related to these indicators are encouraged to take immediate action to mitigate potential impacts and prepare for incident response. This release represents a significant resource for the cybersecurity community in its ongoing battle against phishing threats, providing tangible indicators from one of the most sophisticated phishing operations in recent years.

FBI Reveals Massive Archive of 42,000 Domains from Dismantled Global Phishing Platform, LabHost

In a major move to support the cybersecurity community, the FBI has made public an extensive catalog of 42,000 phishing domains tied to the now-defunct LabHost cybercrime infrastructure—a notorious phishing-as-a-service (PhaaS) platform responsible for facilitating attacks on millions of victims worldwide.

Active between late 2021 and April 2024, LabHost provided a subscription-based toolkit to cybercriminals looking to build and launch realistic phishing campaigns. For as little as $179 per month, nearly 10,000 threat actors gained access to a full suite of services that helped them mimic over 200 trusted organizations—ranging from global banks and government entities to logistics firms and digital entertainment platforms.

The service wasn’t just a phishing website builder—it was a professionally managed ecosystem for digital fraud. Among its most alarming features were proxy-based phishing pages capable of bypassing multi-factor authentication (MFA), integrated SMS phishing (smishing) modules, stolen data collection dashboards, and even a real-time attack monitoring tool dubbed “LabRat.” With these tools, attackers could observe victims live as they entered personal data and intercept one-time passcodes on the fly.

LabHost’s infrastructure held an immense trove of stolen information: more than a million credentials and close to half a million credit card numbers. This data underpinned countless acts of identity theft, fraud, and laundering operations across the globe.

The FBI was able to extract domain information—including creation dates—directly from LabHost’s internal systems after its takedown, which followed a coordinated international crackdown involving Europol and law enforcement agencies from 19 nations. The year-long investigation culminated in 70 global search operations and 37 arrests, including key figures in the UK believed to be at the helm of the service.

Although many of the domains disclosed are no longer active, the FBI stresses their importance as a threat intelligence asset. Cybersecurity teams are urged to comb through historical traffic and logs to identify any links to the exposed domains and take swift remedial steps.

“This dataset offers critical insight into the playbook used by a highly advanced phishing network,” the FBI noted. “Organizations should treat any associations with these domains as a trigger for a thorough investigation and user notification.”

The complete domain list is hosted on the FBI’s Internet Crime Complaint Center (IC3) website. Security professionals are encouraged to reference it as part of broader efforts to defend against phishing campaigns and prepare for emerging threats.

This release marks one of the most substantial pieces of intelligence made public on phishing infrastructure to date—equipping defenders with actionable evidence in the fight against digital deception on a global scale.

More Articles & Posts