Skip to content

Heartsender Spam & Malware Service Dismantled After 10 Years

After 10 years, the notorious Heartsender spam and malware service is finally shut down. The operation resulted in arrests and the seizure of infrastructure across continents.

In this image, we can see an advertisement contains robots and some text.
In this image, we can see an advertisement contains robots and some text.

Heartsender Spam & Malware Service Dismantled After 10 Years

Authorities have dismantled 'Heartsender', a notorious spam and malware service, after a decade of operation. The service, used by transnational organized crime groups, has resulted in over $50m in losses in the US and is linked to 63 cases in Europe. The operation involved arrests in Pakistan and the seizure of technical infrastructure.

The FBI and Dutch Police seized the service's infrastructure in January 2025. The operation, led by Pakistan's National Cyber Crime Investigation Agency (NCCIA), resulted in the arrest of 21 individuals, including Rameez Shahzad, the alleged ringleader. Shahzad previously operated under the guise of 'The Manipulaters' and 'WeCodeSolutions'.

The service, marketed under brands like 'Fudpage' and 'Fudtools', openly advertised phishing kits targeting users of various Internet companies. It was primarily used for business email compromise (BEC) schemes by transnational crime groups. Other persons arrested include Oussama Atar and three unidentified individuals.

The dismantling of Heartsender is a significant blow to cybercriminals. Authorities worldwide are investigating the full extent of the damage caused by the service, with losses in the US alone exceeding $50m. Further details about the arrested individuals and their roles in the operation are expected to emerge as investigations continue.

Read also:

Latest