Tajin Group Exploits Telegram Guarantee Marketplaces
Chinese cybercriminals increasingly abandon the traditional dark web infrastructure. Operations involving sophisticated phishing campaigns, stolen credit card trafficking, money laundering, and the recruitment of accomplices have migrated overwhelmingly to Telegram. Within this messaging platform, criminal syndicates construct robust channels, thriving storefronts, and comprehensive service marketplaces that operate remarkably like legitimate online businesses.
A prominent example of this evolution is the Tajin Group, a highly organized Chinese-speaking syndicate specializing in phishing, carding operations, financial fraud, and the systematic extraction of illicit funds. This group operates prolifically within so-called “guarantee marketplaces,” which have effectively superseded traditional dark web forums within the Chinese cybercriminal ecosystem. These unique marketplaces unite thousands of independent vendors under a centralized system, where a trusted intermediary holds financial deposits in escrow and arbitrates inevitable disputes between participants.
The Massive Scale of Guarantee Marketplaces
The Tajin Group initially peddled its illicit services through the Dabai Guarantee marketplace starting in May 2025 before strategically migrating to the Xinbi Guarantee platform in the spring of 2026. The sheer magnitude of their illicit enterprise is clearly reflected in their staggering vendor deposit. The syndicate boasted a colossal escrow deposit of 208,848 USDT, a figure that dwarfs the paltry hundreds or thousands of USDT typically deposited by standard marketplace participants. For a comprehensive technical analysis of this operation, consult the recent research report detailing the Tajin Group guarantee marketplace ecosystem.
Furthermore, Telegram serves the syndicate as far more than a mere advertising platform. The Tajin Group actively utilized the Fragment platform to purchase premium, collectible usernames and highly anonymous virtual numbers, enabling them to register accounts without requiring traditional SIM cards. Threat analysts definitively linked the group to operations involving over 100 distinct Telegram usernames and multiple virtual numbers. In one notable transaction, the syndicate acquired a single premium number for 1,899 TON, equivalent to approximately 3,054 dollars at the time of purchase.
A Comprehensive Catalog of Illicit Services
The group’s operational portfolio resembles a comprehensive catalog of professional criminal services. The Tajin Group actively facilitates the exploitation of stolen bank cards, illicit money transfers, aggressive cash withdrawals, targeted phishing operations, currency exchange, and sophisticated anti-fraud system circumvention. Furthermore, they heavily promote Ghost Tap schemes utilizing NFC relay transmission techniques. The administrators perpetually recruit partners possessing specialized access to UnionPay, Visa, Mastercard, JCB, and Apple Pay networks, while continuously testing which specific cards and payment gateways remain viable for fund extraction.
A significant portion of their operation intertwines directly with legitimate payment services. The syndicate systematically tested stolen credit cards through platforms like CCAvenue and Geidea, frequently exploiting N-Genius infrastructure and Selfridges electronic gift cards. To evade stringent banking security protocols, the criminals advised their accomplices to deliberately fracture large transfers into smaller, randomized amounts, thereby minimizing the probability of triggering additional fraud checks. Astoundingly, they maintained and updated meticulous lists of vulnerable banks and active BIN prefixes with the precision of professional technical documentation.
The Resilience of Telegram Cybercrime Networks
The investigative team at Recorded Future’s Insikt Group highlighted the alarming professionalization of this illicit marketplace. Vendors routinely debate the precise quality of stolen credit card batches, vociferously complain about their competitors, provide dedicated customer support, frequently rotate their operational partners, and rapidly migrate their entire business infrastructure to alternative Telegram communities when faced with disruptions. Effectively, a robust, compartmentalized infrastructure has coalesced around the messenger, allowing various criminal actors to independently purchase stolen data, sophisticated phishing tools, reliable cash-out mechanisms, and professional money laundering services.
Ultimately, the history of the Tajin Group starkly illustrates the terrifying resilience of this operational model. The sudden disruption or blocking of a single marketplace utterly fails to eradicate the vendors, as these adaptable groups simply transfer their established channels and lucrative client bases to competing platforms. The Xinbi Guarantee marketplace has repeatedly survived severe blockades and resumed operations. However, this past September, United States authorities struck a devastating blow against the platform, aggressively freezing over 52 million dollars in associated cryptocurrency assets.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.