Tajin Group’s channel @ttjt
At a glance
- Actor or group: Tajin Group (suspected Chinese-speaking cybercriminal syndicate)
- Activity type: Phishing, payment card theft, and money laundering
- Targets or victims: Mainland Chinese citizens, global banks, and cryptocurrency exchanges
- Scale: Claimed 208,848 USDT marketplace deposit; processing up to $7,382 per unauthorized withdrawal
- Jurisdiction or law-enforcement status: Active threat group operating on sanctioned platforms (Xinbi Guarantee recently disrupted by the U.S. Treasury)
- Source: Recorded Future Insikt Group and U.S. Department of the Treasury
TL;DR
Threat researchers identified Tajin Group as a major third-party vendor. They operate on Chinese-language guarantee marketplaces. The group actively manages a Tajin Group phishing network. They steal payment card data worldwide. Authorities recently disrupted the Xinbi Guarantee platform. This forced vendors to adapt their operational security to avoid arrest.
What Happened
The cybercriminals initially operated on the Dabai Guarantee marketplace. They later pivoted to Xinbi Guarantee around May 2026. The group posted detailed announcements on Telegram. These messages outlined their illicit services. They rely heavily on the decentralized Fragment Market platform. They buy anonymous virtual numbers using cryptocurrency. They use these numbers to create untraceable Telegram accounts.
The syndicate purchases stolen bank identification numbers from other hackers. They process fraudulent transactions through major payment gateways. Specifically, they target CCAvenue UAE and Geidea. These platforms process their stolen funds. The attackers generate unique payment links to mask their activities. They impersonate legitimate businesses in Dubai to avoid triggering fraud alerts.
They test stolen cards belonging to multiple countries. The criminals maintain a strict list of banned bank identification prefixes. They refuse to process cards from the Middle East, the United States, and Japan. The group avoids these regions because local banks enforce strict 3D Secure authentication protocols. These security checks require a one-time password or biometric confirmation. The attackers cannot bypass these extra layers of security.
The attackers also buy electronic gift cards from retailers like Selfridges. They resell these cards to clean their illicit profits. The operators pay a 45 percent share to the initial card thieves. They keep the remaining profit for themselves.
Who Is Behind It
Security analysts attribute this activity to a Chinese-speaking threat group. This group is known as Tajin Group with high confidence. The moniker translates to ‘stepping on gold’ in Mandarin. The group acts as a service provider within a larger cybercrime ecosystem. They openly advertise their capabilities to other hackers.
According to Recorded Future’s Insikt Group, the criminals are highly organized. The report states: “Tajin Group is mainly involved in phishing, payment card theft, and money laundering.” The researchers also note: “The group actively targeted mainland Chinese citizens and Chinese banks and demonstrated a nuanced understanding of the prerequisites required to transfer funds overseas.”
Tajin Group behaves like a legitimate business. They offer compensation to their criminal clients if their payment gateways go offline. The group provides detailed customer support through private Telegram channels. They even assist clients with cloud-based fund transfers. This level of professionalism attracts many other threat actors. It creates a thriving underground economy centered around financial theft.
The group claimed to hold a deposit of 208,848 USDT on the Xinbi Guarantee platform. This large sum suggests a massive scale of operations. The operators also paid significant amounts in Toncoin for anonymous Telegram handles. One username cost them nearly $150. Another anonymous phone number cost over $3,000. These purchases prove their commitment to operational security.
Impact or Scale
These operations cause severe financial damage. The criminals test stolen cards across platforms in dozens of countries. They claim to bypass security controls on transactions up to 50,000 RMB. That amount equals roughly $7,382 per withdrawal.
The group actively exploits vulnerabilities in banking procedures. They use contactless withdrawal methods and near-field communication relay techniques. They also target airline ticketing systems and luxury jewelry retailers in Hong Kong. By purchasing high-value items, they quickly convert stolen digital funds into physical assets. These assets are then smuggled and sold for clean cash. The global payment industry loses millions of dollars daily to these organized syndicates.
The underlying guarantee platforms facilitate billions in illegal trades. The United States Treasury Department recently sanctioned the Xinbi Guarantee network. Federal authorities seized $52.8 million from wallets connected to the platform. The Justice Department also disrupted the primary Telegram channels hosting these markets.
Despite these law enforcement actions, individual vendors quickly migrate to rival forums. The competition among these criminal service providers remains intense. Tajin Group money laundering services continue to adapt to new restrictions. They continuously seek new partners to supply fresh payment card data. They possess a deep understanding of bank transfer thresholds.
What Comes Next
The disruption of major guarantee platforms forces threat actors to evolve. Criminals will likely increase their use of decentralized tools. Anonymous virtual numbers and blockchain-based usernames make tracking extremely difficult. Law enforcement agencies must collaborate internationally to dismantle these networks.
Financial institutions must monitor transaction patterns targeting Middle Eastern payment gateways. Security teams should flag repeated small-sum transactions that test card validity. Retailers selling electronic gift cards need stricter fraud prevention checks. Banks must also secure their cloud transfer services against unauthorized access.
Consumers must remain vigilant against unsolicited messages requesting payment information. Users should enable step-up authentication on all financial accounts. Reporting suspicious transactions immediately can help freeze stolen funds. Security researchers will continue tracking Tajin Group as they migrate to new platforms.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!