Abstract
Industrial-scale online fraud in Southeast Asia increasingly depends on advanced malware and forced labor. This brief report presents a secondary documentary analysis of publicly available cybersecurity and investigative sources. It applies a human trafficking framework to technical evidence. The primary source is an investigation by Infoblox and Chong Lua Dao, corroborated by (i) The Economist and (ii) the Cyber Scam Monitor profile of K99 Triumph City. The sources document an Android banking trojan linked to K99 Triumph City in Sihanoukville, Cambodia. K99 Triumph City is a scam compound with reported ties to trafficking-based forced labor. The Trojan operates as a malware-as-a-service (MaaS) platform. Documented capabilities include real-time surveillance, credential theft, biometric capture, and fraud. More than 400 lure domains targeting victims in over 20 countries have been identified. Survivors rescued from K99 Triumph City reported beatings and electrocution for missing fraud targets. Screenshots and chat logs reportedly linked tracked domains to operators inside the compound. Cybercrime infrastructure and trafficking-based coercion are structurally intertwined. Anti-trafficking scholarship must therefore engage directly with cybersecurity evidence, methods, and researchers.