Prince Group, also known as the Prince Group Transnational Criminal Organization (Prince Group TCO) and The Prince Group, is a Cambodia-based transnational network associated with large-scale online investment fraud, illegal online gambling, and cryptocurrency money laundering. Led by chairman Chen Zhi, also known as Vincent, the network operates through an extensive international structure of holding companies and affiliated businesses. Its dominant motivation is financial gain. U.S. and U.K. authorities allege that Prince Group controlled scam compounds across Cambodia where trafficked and forcibly detained workers conducted cryptocurrency investment fraud under threats of violence. These operations targeted individuals in the United States and worldwide through romance-baiting or “pig butchering” schemes. Operators cultivated relationships through messaging applications and social media, then directed victims toward fraudulent investments and transferred their funds into accounts controlled by the network. Alleged proceeds were laundered through complex cryptocurrency transfers, payment services, and corporate structures, and converted into luxury assets. Associated businesses include Jin Bei Group, linked to Cambodian casino properties and scam compounds, and Byex and Tian Xu International Technology, sanctioned by the United Kingdom for alleged laundering or financial-service roles. Prince Group-associated entities have also used the illicit Xinbi Guarantee marketplace. On October 14, 2025, the United States and United Kingdom announced coordinated sanctions against the network, with OFAC designating 146 associated targets. U.S. prosecutors charged Chen Zhi with wire-fraud and money-laundering conspiracy and announced the seizure of approximately 127,271 bitcoin, valued at about $15 billion, allegedly controlled by him. Prince Group has denied allegations of illegal activity by its companies and chairman.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Allegedly operated Cambodia-based cyber-fraud compounds that used trafficked or otherwise forcibly held workers to conduct industrial-scale cyber-scamming. The group and its chairman, Chen Zhi, deny the allegations.
A transnational criminal organization whose entities reportedly used Xinbi Guarantee's marketplace services.
A transnational criminal organization whose constituent entities reportedly used the Xinbi marketplace. OFAC actions against the group preceded and informed the Xinbi designation.
Alleged criminal enterprise tied to large-scale scam-center activity, money laundering, and 'pig butchering' fraud proceeds.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.