The Manipulaters

For a decade, if a phishing email slipped past your filters dressed as Microsoft or your bank, there were decent odds the kit behind it was bought off the shelf from a crew in Pakistan. The Manipulaters sold “Fully Un-Detectable” spam and phishing tooling — Fudtools, Fudpage, HeartSender — to fraudsters on every continent, and managed to be undetectable in every direction except their own: they registered scam domains under their real names, celebrated every company anniversary with a cake that said FUD CO in icing and posted the photos to Facebook, let their core domain expire into the hands of a cyber-intelligence firm, and infected their own computers with password-stealing malware. Brian Krebs kept writing it down, and “Saim Raza” kept emailing him — not threats, exactly, just increasingly plaintive demands that the stories come down. They never did. In January 2025 the FBI and Dutch police took the servers; that May, Pakistan arrested 21 of them in Lahore. The takedown requests remain the only part of the operation that never worked even once.

Hello, we already leave that fud etc before year. Why you post us? Why you destroy our lifes? We never harm anyone. Please remove it.

The “Saim Raza” identity — the shared alias behind a decade of “Fully Un-Detectable” phishing tooling — emailing Brian Krebs from a known Saim Raza address (bluebtcus@gmail.com) to demand the FudCo exposé be unpublished. The story stayed up. KrebsOnSecurity, April 2024

WHO
The Manipulaters — a Pakistani phishing-kit, spam-tooling and scam-hosting operation (Karachi, later Lahore), publicly profiled by KrebsOnSecurity from May 2015; brands include Fudtools, Fudpage, Fudsender, FudCo and HeartSender, latterly run behind the Lahore front company We Code Solutions FACT
THE ALIAS
“Saim Raza” — the shared seller identity that peddled the FUD brands across cybercrime forums for a decade; the U.S. DOJ uses the name for the whole group. Krebs's open-source research and Pakistani authorities (via Dawn) identify the alleged ringleader as Rameez Shahzad, boss of We Code Solutions ATTRIBUTED
THE DRAMA
Ten years of catastrophic self-exposure — scam domains registered to their own names, FudCo anniversary cakes posted to Facebook, the core domain allowed to expire into an intelligence firm's hands, their own PCs riddled with credential-stealing malware — punctuated by repeated emails to the reporter covering it, asking him to stop
RECORD
Jan 29, 2025: FBI and Dutch national police seize 39 servers and domains. May 15–16, 2025: Pakistan's NCCIA arrests 21 people in Lahore and Multan; the agency ties the tools to $50M+ in U.S. losses. Charges, not convictions FACT
STATUS
SEIZED — infrastructure gone, 21 defendants awaiting Pakistani justice, and every story they ever asked Krebs to delete still online

This file is not an accusation; the accusations were made by the FBI, the Dutch national police, the U.S. Department of Justice and Pakistan's National Cyber Crime Investigation Agency, and the arrests are theirs. It is a record of the funniest sustained opsec collapse in the phishing economy: a business whose entire product promise was invisibility — “FUD,” Fully Un-Detectable — run by people who could not stop identifying themselves. The through-line is the gap between the brand and the operators: the kits really did evade spam filters, per the agencies that finally seized them, while the people selling them were leaving a ten-year paper trail of WHOIS records, Facebook cake photos and pleading emails to the one reporter guaranteed to publish them.

the drama timeline

ACT I — “BRAND RESEARCH & DEVELOPMENT” (2015–2017)

A phishing crew so brazen it advertises on the open web, registers its scam domains to its own address, and answers the reporter's questions on the record.

  1. MAY 2015

    The calling card

    Krebs profiles the “Manipulaters Team,” a self-described institute for “brand research & development” whose actual catalog is phishing pages for Apple's iCloud and a mess of U.S., European and Asian banks. The opsec tone is set immediately: some 329 scam domains are registered to admin@manipulaters[dot]com, and the group occupies an entire Class C block of internet addresses under its own name. Founder Madih-ullah Riaz of Karachi, when later confronted, insists: “We do not deliberately host or allow any phishing or any other abusive website… we are running business since 2006.”

  2. MAY 2017

    The first takedown plea

    Riaz emails Krebs asking to have his name removed from the 2015 story: “We run web hosting business and due to your post we got very serious problems especially no data center was accepting us… we are not criminals, at least it was not in our knowledge.” The explanation offered: a billing-system error had put the company's own name in the WHOIS records of thousands of scam domains that really belonged to a few bad customers. “2 years of my name in your wonderful article is enough punishment and we learned from our mistakes,” he concludes. The stories stay up; the mistakes, as it turns out, are only beginning.

ACT II — THE CAKE YEARS (2019–2021)

The crew rebrands behind a legitimate-looking software firm in Lahore — then documents its own secret on Facebook, in icing, annually.

  1. 2019

    They forget to renew their own domain

    The Manipulaters let their core domain — manipulaters[dot]com, the one tied to years of business operations — expire. It is promptly scooped up by Scylla Intel, a firm that exists specifically to connect cybercriminals to their real-life identities, which then simply reads the email that keeps arriving for the old owners. “We have them six ways to Sunday as being the guys behind this Saim Raza spammer identity,” Scylla co-founder Sasha Angus tells Krebs. “If they had halfway decent operational security, they could have been really successful. But thankfully, they don't.”

  2. SEPT 2021

    The FudCo cake

    Krebs works backward from the known Saim Raza email addresses to a Lahore software firm, We Code Solutions, whose web server quietly shares hosting with saimraza[dot]tools, fud[dot]tools and heartsender[dot]net. The employees have doxed themselves: every May, Facebook fills with photos of the company anniversary party, gathered around a giant cake with “Fud Co” written in icing. Boss Rameez Shahzad has posted a screenshot of a desktop logged in as Saim Raza, alongside a Skype account starting “game.” and a Gmail starting “bluebtc” — matching Saim Raza's favorite address patterns. The shared password across dozens of Saim Raza accounts, for the record: lovertears.

  3. LATE 2021

    “Why you destroy our lifes?”

    Weeks after the FudCo story, one of Saim Raza's known addresses — bluebtcus@gmail.com — writes to Krebs pleading for deletion: “Hello, we already leave that fud etc before year. Why you post us? Why you destroy our lifes? We never harm anyone. Please remove it.” Krebs, “not wishing to be manipulated by a phishing gang,” ignores it. The group's flagship product at this time openly advertises phishing kits for Microsoft 365, Yahoo, AOL, Intuit, iCloud and ID.me.

ACT III — “I ALREADY LEAVE EVERYTHING” (2024)

The tools get better. The opsec somehow gets worse: the sellers of undetectable malware are discovered to be infected with someone else's.

  1. JAN 14, 2024

    Fresh out of jail, back in Krebs's inbox

    The same address emails again, unprompted: “Please remove this article… Please already my police register case on me. I already leave everything.” Asked to elaborate, the Saim Raza identity says they were freshly released on bail after “many days” in jail, and — of the Pakistani police — offers a review: “There is no good law in Pakistan just they need money.” The claimed retirement is self-reported; what is verifiable is that HeartSender's homepage is still openly advertising phishing kits, now with USPS-themed smishing lures on its Telegram channel.

  2. APRIL 2024

    The exterminators have termites

    DomainTools researchers find that computers associated with The Manipulaters have been massively infected with password-stealing malware for a long time — exposing “vast swaths of account-related data along with an outline of the group's membership, operations, and position in the broader underground economy.” Their customers are infected with the same stealer. The hosted HeartSender service, meanwhile, leaks customer credentials and support tickets to anyone who visits without logging in. DomainTools's deadpan verdict: “Ironically, the Manipulaters may create more short-term risk to their own customers than law enforcement.” Saim Raza's response to Krebs: “First [of] all we never work on virus or compromised computer etc. If you want to write like that fake go ahead.”

ACT IV — THE BILL (2025)

Two governments take the servers. A third takes the people. The stories stay up.

  1. JAN 29, 2025

    The FBI and the Dutch take the keys

    The FBI and the Dutch national police seize 39 servers and domains behind HeartSender, Fudpage, Fudtools and the rest of the FUD constellation. The Dutch say the servers held millions of victim records, including at least 100,000 on Dutch citizens. The DOJ — which refers to the whole operation simply as “Saim Raza” — says the sites “operated as marketplaces that advertised and facilitated the sale of tools such as phishing kits, scam pages and email extractors,” with the main clientele being transnational organized crime groups running business email compromise schemes. Two months earlier, in November 2024, the Saim Raza identity had contacted Krebs one more time to insist they had quit the industry.

  2. MAY 15–16, 2025

    21 arrests in Lahore and Multan

    Pakistan's National Cyber Crime Investigation Agency raids Lahore's Bahria Town and Multan and arrests 21 people accused of operating HeartSender — among them, per Dawn, alleged ringleader Rameez Shahzad and his father. The NCCIA ties the group's tools to more than $50 million in U.S. losses, with European authorities investigating 63 further cases. “This wasn't just a scam operation – it was essentially a cybercrime university that empowered fraudsters globally,” NCCIA Director Abdul Ghaffar tells reporters. They are charges, not convictions — but the man Krebs identified from a Facebook cake photo in 2021 is now in custody under the same name.

both sides, on the record

The case: for at least a decade, The Manipulaters openly sold the industrial inputs of phishing — “Fully Un-Detectable” sender tools, scam-page kits for Microsoft 365, Yahoo, AOL, Intuit, iCloud and ID.me, hosting for all of it — first under their own names, then behind the We Code Solutions front. The FBI and DOJ say the clientele was transnational organized crime running business email compromise; the Dutch found millions of victim records on the seized servers; Pakistan's NCCIA puts U.S. losses above $50 million and calls the operation “a cybercrime university.” The decade of Krebs reporting — WHOIS trails, the shared hosting, the Saim Raza screenshots, the cakes — is open-source and has never been rebutted with anything more specific than “please remove it.”

The farce is the aggravator: they were warned, by name, in public, in 2015, 2021 and 2024, and kept going each time — pausing only to email the reporter asking him to delete the warnings.

The defense, as stated by the subjects: Riaz maintained from the start that they ran a legitimate hosting business since 2006, removed abusive sites on complaint, and that a billing-system error — not criminality — put their name on customers' scam domains: “we are not criminals, at least it was not in our knowledge.” The Saim Raza identity has insisted since 2021 that the group left the FUD business, that they “never harm anyone,” and that the Pakistani police pursuing them were shaking them down for money rather than enforcing any real law.

And the record is not finished: nobody in this file has been convicted of anything. The 21 arrested in May 2025 are accused; the real-name identifications rest on journalist and researcher open-source work plus the NCCIA's charging decisions, not on a court's verdict. The sentence, if any, is still ahead.

YOU DECIDE

Every seller of invisibility eventually has to answer the obvious question: if the product works, why can everyone see you? The Manipulaters spent ten years marketing Fully Un-Detectable crimeware while being the single most detectable organization in the phishing economy — identified by their own WHOIS records, their own Facebook, their own expired domain, their own infected computers, and finally their own emails to the one man on the internet guaranteed to publish them. Maybe the 21 arrests collapse; maybe the defense's billing-error decade holds up in a Lahore courtroom. But the drama here was never really the fraud. It was the correspondence: a crew that could evade every spam filter on earth except Brian Krebs's inbox, where it kept voluntarily filing evidence.

The archive does not deify. It keeps the cake photos — and every takedown request, unanswered.

evidence locker

PRIMARY / THE KREBS FILE (2015–2024)

  1. KrebsOnSecurity — “Phishing Gang is Audacious Manipulator” FACT — the May 2015 original: the “brand research” site copy, the 329 domains registered to admin@manipulaters[dot]com, the Class C block, and the naming of founder Madih-ullah Riaz. krebsonsecurity.com/2015/05/phishing-gang-is-audacious-manipulator/
  2. KrebsOnSecurity — “FudCo Spam Empire Tied to Pakistani Software Firm” FACT — the September 2021 exposé: We Code Solutions, the shared hosting with saimraza[dot]tools and heartsender[dot]net, the FudCo cakes, Rameez Shahzad's Saim Raza screenshot, the “lovertears” password, the 2019 expired domain and Scylla Intel's “six ways to Sunday,” plus Riaz's 2015 and 2017 statements. krebsonsecurity.com/2021/09/fudco-spam-empire-tied-to-pakistani-software-firm/
  3. KrebsOnSecurity — “The Manipulaters Improve Phishing, Still Fail at Opsec” FACT — the April 2024 check-in: the verbatim takedown emails from bluebtcus@gmail.com (2021 and January 2024), the self-reported jail-and-bail account, and the DomainTools findings on the stealer-infected Manipulaters PCs and the credential-leaking HeartSender interface. krebsonsecurity.com/2024/04/the-manipulaters-improve-phishing-still-fail-at-opsec/

THE TAKEDOWN (2025)

  1. KrebsOnSecurity — “FBI, Dutch Police Disrupt ‘Manipulaters’ Phishing Gang” FACT — the January 29, 2025 seizure of 39 servers and domains, the millions of victim records (100,000+ Dutch), and the DOJ's description of the Saim Raza marketplaces and their BEC clientele. krebsonsecurity.com/2025/01/fbi-dutch-police-disrupt-manipulaters-phishing-gang/
  2. U.S. Department of Justice (S.D. Tex.) — seizure announcement FACT — the agency's own statement on the seizure of the Saim Raza / HeartSender cybercrime websites sold to transnational organized crime groups. justice.gov/usao-sdtx/pr/cybercrime-websites-selling-hacking-tools-transnational-organized-crime-groups-seized
  3. Politie (Dutch national police) — HeartSender disruption notice FACT — the Dutch statement on the joint action against the HeartSender network and the ongoing investigation into the service's buyers. politie.nl — verstoringsactie cybernetwerk HeartSender
  4. KrebsOnSecurity — “Pakistan Arrests 21 in ‘HeartSender’ Malware Service” FACT — the May 2025 NCCIA raids in Lahore and Multan, the 21 named defendants including Rameez Shahzad, the $50M+ U.S.-loss figure, and the November 2024 “turned over a new leaf” contact. krebsonsecurity.com/2025/05/pakistan-arrests-21-in-heartsender-malware-service/
  5. Dawn — NCCIA arrests report ATTRIBUTED — Pakistani-press reporting of the arrests, the alleged ringleader identification, and NCCIA Director Abdul Ghaffar's “cybercrime university” briefing. dawn.com/news/1911691

CONTEXT & CROSS-LINKS

  1. troll.fan — vDOS CROSS-LINK — the criminal-service sibling: another crime-as-a-subscription shop unmasked through Krebs's inbox, with the same lesson about empires that keep their own logs. troll.fan/dossiers/vdos.html
  2. troll.fan — Crew Rivalries CROSS-LINK — the wider culture of crews whose worst enemy is reliably themselves. troll.fan/crew-rivalries.html
  3. troll.fan — Timeline CROSS-LINK — The Manipulaters' 2015–2025 run in the scene's wider chronology. troll.fan/timeline.html
The standard. The Manipulaters are a documented public matter: the decade of open phishing-tool sales, the 2019 domain lapse, the 2021 We Code Solutions findings, the 2024 DomainTools research, the January 2025 FBI/Dutch seizure and the May 2025 arrest of 21 people in Pakistan are stated per KrebsOnSecurity's reporting, DomainTools' published research, and the statements of the DOJ, the Dutch national police and Pakistan's NCCIA. Madih-ullah Riaz is named because Krebs's 2015 reporting named him and he responded on the record; Rameez Shahzad is named because Krebs's 2021 open-source research identified him and Pakistani authorities later arrested him under that name — his link to the “Saim Raza” alias is reported as those sources' finding, not a court's. Every arrest on this page is a charge, not a conviction, and is labeled so. First-party quotes are reproduced from emails to KrebsOnSecurity as published there, attributed to the identity that sent them; the jail and retirement claims are self-reported and marked as such. No victim data is reproduced and no phishing mechanics are described — the tools are documented by what their own advertising promised. If a line here couldn't survive scrutiny, it wouldn't be on the page.