Penguin Account Store, also known as Heavenly Alliance and Overseas Alliance, is a Chinese-speaking cybercriminal service provider associated with the pig-butchering-as-a-service ecosystem. It operates a crimeware-as-a-service model that supplies infrastructure and operational tooling used to enable large-scale romance-baiting and investment fraud, particularly within Southeast Asia-linked scam-center environments. The actor is known for selling stolen personal-information datasets, pre-registered online accounts, bulk SIM cards, device and telecom-enablement tooling, and packages of stolen images used to construct fraudulent personas. It also offers social-media customer relationship management tooling branded as SCRM AI, designed to automate or streamline victim engagement across social platforms. In addition, the actor advertises payment-processing support through BCD Pay, an anonymous peer-to-peer payment solution linked in reporting to Bochuang Guarantee and described as having roots in illegal online gambling. Penguin Account Store’s offerings lower the barrier to entry for fraud operators by providing turnkey scam components rather than conducting only bespoke intrusions. Its services support initial access to victim communications, large-scale social engineering, operational persistence in scam workflows, and monetization through payment and account infrastructure. Reporting indicates that credentials and account data sold by the actor are believed to derive from information-stealer logs traded in criminal markets, but there is no high-confidence evidence that Penguin Account Store itself develops or operates information stealers. The actor’s role is best understood as an enabling supplier within a broader transnational fraud ecosystem rather than a traditional espionage or ransomware intrusion set. Its activity is closely aligned with financially motivated scam operations that rely on stolen identities, spoofed personas, automated engagement platforms, and fraud-support services to industrialize online deception.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.