Carding & Financial Fraud

SkillCommerce & finance

Use when the user asks about carding, BIN attacks, payment-card breach markets, fullz/CVV2 trade, autoshops (BidenCash, Brian's Club, Russianmarket, B1ack's Stash), or financial-fraud TTPs. Self-updating knowledge cell.

Use Carding & Financial Fraud in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Carding & Financial Fraud and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Carding & Financial Fraud skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Carding & Financial FraudStart free

What this skill tells your AI

The instructions your AI receives, as published by liberty91ltd/cti-skills in skills/carding-financial-fraud/SKILL.md and read by Ahel’s review.

Executive Summary

Carding and financial fraud represent one of the oldest and most mature cybercriminal ecosystems, encompassing the theft, trade, and monetization of payment card data and financial credentials. The ecosystem spans from initial data theft (via digital skimming, phishing, POS malware, and database breaches) through underground marketplace trading to monetization via card-not-present (CNP) fraud, mobile wallet fraud, money mule networks, and reshipping schemes. CNP data still dominates the underground card market, but card-present fraud has returned in a new form: stolen cards provisioned into Apple and Google wallets and used or relayed over NFC [11][13].

The card shop landscape changed materially in 2025. BidenCash, previously the most visible shop, was seized on June 4, 2025 by the US Secret Service and FBI with Dutch police support (about 145 domains; no arrests announced) [9]. In September 2025 the Manhattan District Attorney seized 12 domains belonging to five further vendors, including B1ack's Stash, but Recorded Future assesses that most of those shops kept posting card data on related domains [10][11]. B1ack's Stash took over BidenCash's free-dump marketing tactic and released a further 4.6 million records in May 2026 [12]. Recorded Future counted about 142 million card records posted for sale on dark web marketplaces in 2025, down 19% from 2024, while freely exposed records on Telegram and other sources rose 26% to a comparable volume, and 82% of for-sale CNP records came with victim contact details [11].

The most significant shift in technique is the Chinese-language fraud ecosystem. Smishing kits such as Lighthouse, Darcula and Lucid harvest card data and one-time codes, enroll the cards in mobile wallets on attacker-controlled phones, and cash out in stores or through NFC relay ("ghost tap") tools sold as a service on Telegram [13][14][17]. Google sued the Lighthouse operators in November 2025 and the service reported its servers blocked within days, though researchers expected the activity to continue under other names [15][16]. NFC relay malware has since spread beyond Chinese-speaking vendors to independently developed families in Europe and Latin America [18][20].

Web skimming (Magecart) remains stable at scale rather than declining: Recorded Future tracked more than 10,500 active e-skimmer infections in 2025 despite the PCI DSS 4.0 script-integrity requirements taking effect, with skimmer kits and skimming-as-a-service lowering the barrier to entry [11]. The fraud ecosystem continues to overlap with infostealers, Business Email Compromise (BEC), SIM swapping and Fraud-as-a-Service (FaaS) offerings, and in 2026 researchers documented AI agents being used to automate retailer compromise and skimmer deployment [28].

Key Actors

Actor/EntityTypeNotable CharacteristicsStatus
BidenCashCard ShopOperated from March 2022; marketed via large free card dumps. Per US authorities: 117,000+ customers, 15M+ card numbers trafficked, $17M+ revenue [9]Seized June 4, 2025; no arrests announced
B1ack's StashCard ShopActive since at least 2023; adopted the free-dump marketing tactic (2024, 2025, May 2026); named in Manhattan DA domain seizure of September 2025 [10][11][12]Active (disrupted, continued operating)
SIKTOR, PP24, CVVUNION, VCLUBCard ShopsSmaller vendors whose domains were seized by the Manhattan DA alongside B1ack's Stash [10]Disrupted September 2025; current status unconfirmed
Joker's StashCard ShopFormerly dominant card shop; voluntarily retired February 2021Defunct
BriansClubCard ShopMajor card shop; was itself breached in 2019 exposing 26M card recordsStatus unclear
Genesis MarketCredential/Bot MarketSold browser fingerprints and credentials; seized in Operation Cookie Monster April 2023Seized
Russian MarketLog/Credential ShopOperating since 2020; Rapid7 describes infostealer logs as its main offering (180,000+ logs offered in H1 2025), with card data a secondary line [26]Active
Smishing Triad / Lighthouse, Darcula, Lucid, XinxinChinese-language phishing-as-a-serviceSMS/iMessage/RCS phishing kits that harvest card data and one-time codes for mobile wallet provisioning [13][14][15]Active; Lighthouse disrupted November 2025
TX-NFC, X-NFC, NFU PayNFC relay Fraud-as-a-ServiceChinese-language vendors selling "ghost tap" relay apps by subscription on Telegram; tracked by Group-IB [17]Active
Magecart GroupsDigital Skimming CollectiveUmbrella term for multiple groups conducting web-based card skimming; increasingly kit- and service-based (Sniffer by Fleras, AcceptCar) [11]Active (various)
FIN7Cybercrime GroupSophisticated group with ties to POS malware (Carbanak/FIN7 campaigns); members arrested but operations continuedPartially disrupted
Scattered SpiderCybercrime CollectiveSIM swapping, social engineering, extortion; young Western actors. Multiple members convicted 2025-2026; the NCA said the September 2025 arrests effectively halted the group's activity [27]Degraded
Various BEC NetworksFraud OperationsWest African (Yahoo Boys) and Eastern European networks conducting BEC and romance fraudActive
SIM Swapping CrewsAccount TakeoverLoosely organized groups bribing telecom employees or exploiting SS7Active

Current Activity

Card Shop Disruption and Free Dump Marketing

With BidenCash seized in June 2025, no single shop holds the position it once did. Recorded Future notes that the seizure followed a steady decline in BidenCash's market share, and that takedowns affecting at least five other marketplaces had limited effect because most resumed posting on related domains [11]. B1ack's Stash continues the free-dump tactic: a release in February 2025 (3.5 million records per Recorded Future; "over 4 million" per SecurityWeek), a second 2025 release of 1.7 million, and 4.6 million in May 2026 [11][12]. SOCRadar assessed about 4.3 million of the May 2026 records as new and roughly 70% as US-issued; the shop presented the release as a penalty against sellers who resold its stock elsewhere [12]. Card records exposed for free on Telegram and other sources now match the dark web shops' for-sale volume [11].

Smishing-Driven Mobile Wallet Provisioning

China-based phishing-as-a-service groups send toll, parcel and bank lures over SMS, iMessage and RCS. Victims enter card details and then a one-time code, which the operators use to enroll the card in a mobile wallet on a phone they control. Researchers report several wallets loaded per device and a wait of 7-10 days before use or resale of the phone [13][15]. Google's November 2025 complaint says Lighthouse offered over 600 templates imitating more than 400 entities and harmed more than a million victims in 120 countries; its estimate of cards stolen in the US ranges from 12 million to 115 million, so the true figure is uncertain [15][16]. Silent Push observed about 25,000 phishing domains active in any 8-day period [14][15].

NFC Relay and "Ghost Tap" Fraud

NFC relay fraud passes contactless payment data from a stolen card or provisioned wallet to a mule's device at a point-of-sale terminal or ATM in another location. ThreatFabric documented ghost tap in November 2024 [13][21]. Two variants exist: relay of cards already stolen through phishing, where the victim's device is never infected [17], and Android malware that persuades victims to tap their own card against an infected phone (NGate, SuperCard X, PhantomCard, WindRelay) [18][19][29]. Group-IB identified more than 54 relay app variants and at least $355,000 in illegitimate transactions through one POS vendor between November 2024 and August 2025 [17]. In May 2026 Cleafy reported two independently built families, DevilNFC and NFCMultiPay, attributed to Spanish- and Portuguese-speaking developers and showing signs of AI-assisted development [20]. In August 2026 Group-IB reported WindRelay, delivered with a SpyNote variant during vishing calls against victims in Czechia, Slovakia, Slovenia and Poland [18].

Magecart/Digital Skimming Evolution

Digital skimming has industrialized. Recorded Future counted more than 10,500 unique e-skimmer infections active in 2025 (7,300 of them new), likely compromising over 23 million transactions, and attributed 26% of infections to a single commercial kit, Sniffer by Fleras [11]. The PCI DSS 4.0 requirement 6.4.3 (client-side script integrity monitoring) took effect in March 2025, but Recorded Future found no corresponding decrease in Magecart impact [11]. Recent campaigns abuse trusted services to evade allowlists: Silent Push exposed a skimming network active since early 2022 (January 2026) [24], and Sansec reported a skimmer hidden in SVG elements on 99 Magento stores (April 2026) and a campaign using Google Tag Manager and a payment processor's API for delivery and exfiltration (June 2026) [22][23]. In September 2026 Gambit reported a Chinese-speaking operator using open-source AI agent frameworks to compromise retailers and deploy skimmers at an estimated cost of about $25 per target; Gambit cautions that its analysis is early-stage [28].

Card Testing and Purchase Scams

Recorded Future identified more than 1,350 merchants abused for card testing in 2025, 94% of them not seen before, and at least 27 million card records exposed through Telegram-based generation and testing services that can support BIN attacks. It also identified more than 3,600 scam merchant accounts used in purchase scams, where victims authorize the payment themselves [11].

SIM Swapping and Account Takeover Escalation

SIM swapping attacks have expanded beyond cryptocurrency theft to target traditional financial accounts, corporate accounts, and even government officials. Techniques include bribing or socially engineering telecom employees, exploiting eSIM provisioning vulnerabilities, and using SS7 protocol weaknesses. Several high-profile prosecutions have followed (see Historical Events), but the technique remains prevalent due to the fundamental weakness of SMS-based authentication. One-time password interception more broadly is now a standard component of wallet and relay fraud [11].

Historical Events

DateEventImpact
2018British Airways Magecart breach380,000 card details stolen via injected checkout script; ICO fined BA £20M
2019BriansClub breach26M stolen card records from the card shop itself were leaked; data shared with banks
Feb 2021Joker's Stash retirementLargest card shop voluntarily closed; created market fragmentation
Apr 2023Operation Cookie Monster (Genesis Market)FBI-led takedown seized Genesis Market; 119 arrests globally; disrupted bot/fingerprint market
2022-2025BidenCash free dumpsRepeated free releases of stolen card data as marketing, including 3.3M cards between October 2022 and February 2023 [9] and 910,000 in April 2025 [11]
2024PCI DSS 4.0 transitionNew requirements for client-side script monitoring; full enforcement March 2025
2024-2025FIN7 members sentencedMultiple FIN7 members received significant prison sentences in US courts
2024-2026Scattered Spider prosecutionsNoah Urban sentenced to 10 years (August 2025); Tyler Buchanan pleaded guilty in the US (April 2026); Thalha Jubair and Owen Flowers each sentenced in the UK to five years and six months (July 2026) [27]
Feb 2025B1ack's Stash free dumpRelease of 3.5M to 4M+ card records (sources differ) as marketing [11][12]
Apr 2025SuperCard X disclosedCleafy exposed a Chinese-speaking malware-as-a-service for NFC relay fraud, first seen targeting Italy [19]
Jun 4, 2025BidenCash seizureUS Secret Service and FBI, with Dutch police, Shadowserver and Searchlight Cyber, seized about 145 domains and cryptocurrency; no arrests announced [9]
Sep 22, 2025Manhattan DA domain seizures12 domains of five card vendors (SIKTOR, PP24, CVVUNION, VCLUB, B1ack's Stash) seized; more than 1M cards involved; investigation ongoing [10]
Nov 4, 2025Operation ChargebackGerman-led action coordinated by Europol and Eurojust against three networks accused of misusing card data of 4.3M cardholders (EUR 300M damage, 2016-2021); 18 arrests including payment service provider executives [25]
Nov 12, 2025Google v. LighthouseCivil suit (RICO, Lanham Act, CFAA) against 25 unnamed defendants; Lighthouse reported its servers blocked within days [15][16]
Jan 2026Ghost Tapped researchGroup-IB published its analysis of Chinese tap-to-pay relay vendors [17]
May 2026B1ack's Stash 4.6M dumpLargest free release by the shop to date, eight months after its domains were seized [12]

TTP Evolution

Data Theft Methods: The ecosystem has evolved from physical skimming devices and POS RAM scraping malware (2010s) to predominantly web-based digital skimming (Magecart-style JavaScript injection) and mass data theft via infostealer malware. Server-side skimmers that intercept payment data at the application layer are increasingly common, as they evade client-side Content Security Policy (CSP) and script monitoring solutions.

Mobile Wallet and NFC Abuse: Since 2024 the main innovation has been converting phished card data into mobile wallet tokens and relaying NFC transactions to mules. This restores card-present fraud without cloning a chip, and wallet transactions tend to be treated as trusted. Recorded Future identifies the card provisioning attempt as the most reliable point for detection; Krebs' sources recommend that issuers require in-app authentication rather than SMS codes for provisioning [11][13].

Marketplace Infrastructure: Card shops have moved from forums with manual transactions to automated platforms with APIs, validity checkers (testing cards with small transactions), replacement guarantees (refunds for dead cards), and sophisticated search/filter capabilities. Multi-vendor marketplaces now coexist with single-operator shops. Telegram channels serve as both advertising and direct sales channels.

Monetization: CNP fraud techniques include using residential proxies to match cardholder geolocation, anti-fingerprinting browsers (Multilogin, GoLogin) to evade device fingerprinting, and automated checkout bots for rapid purchases. Gift card purchasing remains a primary cashout method. Cryptocurrency purchasing using stolen cards provides another laundering avenue.

Money Mule Operations: Recruitment of money mules has shifted from in-person "work from home" scams to social media and messaging app recruitment. Professional mule herders manage networks of mules across countries. Mules receive fraudulent funds and forward them, taking a commission. Some operations use cryptocurrency ATMs for rapid conversion.

Identity Fraud (Fullz): Complete identity packages ("fullz") containing name, SSN, DOB, address, email, phone, and sometimes bank credentials trade for $15-$65 depending on credit score and completeness. Synthetic identity fraud — combining real and fabricated data to create new identities — is a growing trend that is harder to detect than traditional identity theft.

Ecosystem & Infrastructure Patterns

Supply Chain: Card data flows from theft (skimming, breaches, infostealers) → aggregation by data brokers → card shop listings → purchase by carders → monetization via CNP fraud or resale. Each stage has specialized actors, and data may pass through multiple intermediaries before final use.

Quality Assurance: Card shops offer "checker" services that validate cards are still active by running small authorization charges. Cards are priced by freshness, bank, type (credit vs. debit), level (Classic, Gold, Platinum, Corporate), and geographic region. Corporate and high-limit cards command premium prices ($20-$100+).

Fraud-as-a-Service: Turnkey fraud packages include phishing kits targeting specific banks, fraud tutorials, pre-configured anti-detect browsers with stolen cookies/fingerprints, residential proxy access, and money mule network access. These services democratize fraud, enabling low-skill operators to conduct sophisticated attacks.

Geographic Patterns: Major carding actor concentrations include Russia/CIS (card shop operators, malware developers), West Africa (BEC, romance fraud, money mules), Southeast Asia (scam compounds, pig butchering operations), and Western countries (SIM swapping, money mule recruitment). Fraud scam compounds in Myanmar, Cambodia, and Laos have drawn international attention for human trafficking elements.

Tooling

ToolCategoryUsage
Magecart skimmersData TheftJavaScript injections into e-commerce checkout pages; sold as kits and services (Sniffer by Fleras, AcceptCar) [11]
Smishing kits (Lighthouse, Darcula, Lucid)Data TheftPhishing-as-a-service harvesting card data and one-time codes for wallet provisioning [14][15]
NFC relay apps (NFCGate derivatives, Z-NFC, TX-NFC, SuperCard X, PhantomCard, WindRelay)MonetizationRelay contactless transactions to mule devices at POS terminals and ATMs [13][17][18][19]
Anti-detect browsers (Multilogin, GoLogin)Fraud ToolingSpoof browser fingerprints to evade fraud detection
Residential proxies (911.re successors, various)InfrastructureMatch cardholder geolocation for CNP fraud
SMS interceptors / SS7 toolsAccount TakeoverIntercept 2FA codes for bank account takeover
Card checker servicesValidationVerify card validity before use
Infostealer logsData SupplyLumma, Rhadamanthys, Acreed and others feeding card/credential markets [26]
POS malware (various)Data TheftRAM scraping on point-of-sale terminals (declining)
E-commerce botsMonetizationAutomated checkout for rapid fraudulent purchases
Telegram botsMarketplaceAutomated card shops and checker services via Telegram
Cashout guides/tutorialsKnowledgeStep-by-step fraud methodology documentation

Intelligence Gaps

  • Scam compound scale: The true scale and financial impact of Southeast Asian scam compounds (pig butchering, investment fraud) is poorly quantified, though estimates suggest tens of billions in annual losses.

  • Synthetic identity fraud volume: The prevalence of synthetic identity fraud is difficult to measure because many losses are misclassified as credit losses rather than fraud losses by financial institutions.

  • Cryptocurrency intersection: The overlap between traditional carding/fraud operations and cryptocurrency-focused theft (exchange account takeover, DeFi exploitation) is not well-mapped.

  • Real-time card fraud attribution: Attributing specific card fraud transactions to specific card shop purchases or breach events remains extremely difficult for law enforcement and financial institutions.

  • Fraud-as-a-Service market size: The total revenue of FaaS platforms and their contribution to overall fraud losses is not well-estimated.

  • BriansClub status: Unconfirmed. No primary source opened in the September 2026 refresh establishes whether the shop is operating; secondary listings describe repeated disruption and domain churn.

  • FIN7 current activity: Not re-verified in the September 2026 refresh; the status above is carried over from the baseline.

  • Operators behind seized shops: No arrests were announced for BidenCash or the vendors named by the Manhattan DA, and the operators remain publicly unidentified [9][10].

  • Lighthouse after the lawsuit: Whether the service resumed under the same or another name is not confirmed; estimates of cards stolen vary by an order of magnitude [15][16].

  • Ghost tap losses: Published loss figures cover single vendors or campaigns; no aggregate loss estimate for NFC relay fraud was found.

  • Baseline figures: The CNP loss estimate in earlier versions of this cell and the Genesis Market arrest count were not re-verified.

Sources & References

Shortened here. Read the whole file on GitHub.

Signals

GitHub stars
27
Forks
8
Last commit
Sep 2026
Advanced
Item type
skill
Key
carding-financial-fraud
Source
github.com/liberty91ltd/cti-skills