www.group-ib.com Mule-as-a-Service: Evolving Threat in Cybercrime and Money Laundering
Article Content
- •Mule-as-a-Service (MaaS) ecosystems are transforming money laundering operations.
- •Latin America, especially Brazil, is a growing center for money mule activities.
- •Financial institutions must adapt to new AI-driven laundering techniques.
Money mule networks are increasingly professionalized through Mule-as-a-Service (MaaS) ecosystems, enabling cybercriminals to launder funds from various scams such as phishing and ransomware. These operations utilize stolen and synthetic identities, automated onboarding, and AI-assisted techniques to create resilient laundering infrastructures. Latin America, particularly Brazil, is becoming a significant hub for these activities, with real-time payment systems facilitating money laundering through 'Contas Laranja' accounts. The financial impact of money laundering is substantial, with cumulative losses estimated at $1.6 trillion globally. In the U.S., about 0.3% of financial institution accounts are believed to be mule-controlled, indicating a growing trend. The shift towards automated and AI-enabled money mule operations necessitates a change in how financial institutions monitor and detect fraudulent activities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…