# Tajin Group and Chinese Telegram Guarantee Marketplaces

> Analysis of the Tajin Group operating on Dabai and Xinbi guarantee marketplaces, detailing money laundering, phishing, and OPSEC tactics.

- Published: 2026-10-01T20:52:50.000Z
- Severity: info
- Category: Threat Intel
- Tags: Tajin Group, Phishing, Ransomware, Money Laundering, Telegram
- Author: Runtime Rebel Intel
- Primary source: https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace
- Canonical: https://runtimerebel.com/blog/tajin-group-and-chinese-telegram-guarantee-marketplaces

## Key points

- Financial institutions, cryptocurrency exchanges, and individuals face heightened risks from phishing, carding, and money laundering campaigns orchestrated by the Tajin Group.
- The threat group operates extensively across Telegram-based Chinese-language guarantee marketplaces, specifically Dabai Guarantee and Xinbi Guarantee.
- Defenders must monitor and restrict unauthorized financial transactions, analyze suspicious cryptocurrency movements, and implement strict threat intelligence feeds targeting illicit Telegram channels.

## Overview of Tajin Group Operations

Recent intelligence research published by [Recorded Future](https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace) details the operational mechanics of the Tajin Group (踏金集团), a Chinese-speaking threat syndicate specializing in [phishing](/glossary#phishing), payment card theft, financial fraud, and money laundering. Tajin Group functions as a high-tier third-party vendor within Chinese-language Telegram-based guarantee marketplaces, serving as a vital node in the broader cybercrime ecosystem.

Guarantee marketplaces have emerged as prominent alternatives to traditional [dark web](/glossary#dark-web) forums, providing escrow services, dispute resolution, and vendor accountability via cryptocurrency deposits. Tajin Group maintained a presence on the Dabai Guarantee marketplace before migrating its operations to the Xinbi Guarantee marketplace, adhering to ecosystem rules that restrict vendors from operating across multiple competing escrow platforms simultaneously.

## Technical Details and Evolving TTPs

### Advanced Operational Security (OPSEC)

To evade detection and maintain [persistence](/glossary#persistence) across messaging platforms, Tajin Group and similar threat actors leverage specialized third-party services to acquire Telegram collectible usernames and anonymous virtual numbers. By bypassing traditional physical SIM card requirements, these operators link multiple digital identifiers to unified accounts, establishing scalable infrastructures for large-scale phishing and [social engineering](/glossary#social-engineering) campaigns.

### Financial Scale and Collateral

Vendor credibility within Telegram guarantee marketplaces is frequently measured by staked cryptocurrency deposits. While typical vendors stake modest amounts ranging from several hundred to a few thousand Tether (USDT), Tajin Group reported a substantial collateral deposit of 208,848 USDT on Xinbi Guarantee. This elevated financial commitment reflects a large-scale enterprise capable of sustaining high-volume carding operations and complex money laundering topologies involving 2D and 3D payment gateways.

## Impact on Global Financial Systems

The activities of guarantee marketplace vendors directly threaten commercial banks, digital payment providers, and cryptocurrency exchanges. Because these marketplaces function as force multipliers for recruitment, resource sharing, and crowdsourced cybercriminal capabilities, successful operational models adopted by syndicates like Tajin Group are frequently replicated by competing threat groups globally.

## Mitigations and Defensive Recommendations

Security teams and financial institutions should prioritize the following defensive postures:

* Enhance transaction monitoring rules to identify velocity anomalies associated with carding operations and fraudulent gateway interactions.
* Incorporate [threat intelligence](/glossary#threat-intelligence) feeds that monitor emerging Telegram-based guarantee marketplaces and associated cryptocurrency wallet addresses linked to high-value escrow deposits.
* Implement strict behavioral analysis on inbound communications and authentication requests to detect [credential harvesting](/glossary#credential-harvesting) and targeted phishing campaigns.

**Related:** [UNC6671 Rebrands: Multi-Brand Vishing and Cloud Extortion](/blog/unc6671-rebrands-multi-brand-vishing-and-cloud-extortion), [Talos Q2 2026 Report: Phishing and Living-off-the-Land Trends](/blog/talos-q2-2026-report-phishing-and-living-off-the-land-trends)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/tajin-group-and-chinese-telegram-guarantee-marketplaces
