PayTool is a financially motivated phishing and smishing threat actor or fraud ecosystem focused on Canadian victims. It is associated with large-scale impersonation of trusted Canadian public-sector entities and major brands, including government traffic and fine-payment services, postal delivery services, tax-related themes, and airline booking workflows. The operation is notable for high-fidelity social engineering that pressures victims with claims such as unpaid fines, delivery failures, booking problems, or license-related issues, then routes them to fraudulent portals designed to harvest personally identifiable information, payment card data, and online banking credentials. A defining characteristic of PayTool activity is SMS-based social engineering tied to traffic violation and fine-payment scams. Victims are commonly directed to fake government-style portals that simulate centralized public services and then branch into province-specific payment workflows, increasing credibility through localized branding. Reported lures have impersonated services associated with provinces including British Columbia, Ontario, Quebec, Manitoba, Saskatchewan, and Alberta, as well as transportation-related entities such as 407 ETR. The actor also uses Canadian phone numbers and provincial branding to improve conversion rates. The ecosystem demonstrates operational maturity through bulk domain generation, typosquatting, URL-shortener abuse, and resilient infrastructure rotation. Province-themed phishing sites are supplemented by generic fallback payment and infraction portals that can be swapped in when themed infrastructure is blocked. A separate but related cluster has targeted travelers by impersonating Air Canada through SEO poisoning and typosquatted booking sites, while another cluster has used Canada Post delivery and redelivery themes. These campaigns clone legitimate branding and user flows rather than relying on simplistic single-page credential prompts. PayTool has also been linked to a phishing-as-a-service model in which tooling is commoditized and sold to other criminals. Underground sales activity associated with the alias theghostorder01 has advertised phishing kits that mimic Canadian service workflows such as driver’s license renewal and are intended to capture PII, card data, and Interac e-Transfer credentials for rapid account takeover and fraud. Overall, PayTool is best characterized as a Canadian-focused fraud ecosystem specializing in credential theft and financial-data harvesting through scalable, brand-impersonation phishing operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Fraud/phishing ecosystem used to run high-fidelity impersonation campaigns (Government of Canada/provincial fine payment portals, Canada Post-style lures) primarily via smishing, with resilient domain rotation to sustain operations when domains are blocked.
Phishing/smishing ecosystem impersonating Canadian provincial/federal traffic ticket and fine-payment services (e.g., PayBC, ServiceOntario, 'Traffic Ticket Search Portal – Government of Canada') and expanding into adjacent brand-impersonation fraud (Canada Post parcel/redelivery and Air Canada booking). Uses fake validation steps followed by fraudulent payment pages to harvest PII and financial data (credit cards, Interac e-Transfer credentials). Maintains reusable templates, bulk-registered/keyword domains, and shared hosting to enable rapid rotation when domains are blocked.
PayTool is conducting large-scale SMS phishing (smishing) campaigns targeting Canadians with traffic-related scams. They impersonate government agencies and private firms to steal personal and financial information, which is then used for fraudulent purchases and currency conversion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.