Lau Chun Kiat was sentenced on May 25, 2024, to five years and five months in jail after pleading guilty to charges of being part of an organised criminal group and conspiracy to gain access to devices through malware [1, 2, 3].

The 28-year-old Malaysian maintained a scam syndicate’s physical office in Kuala Lumpur and made payments for hosting multiple servers used to run remote access malware targeting victims in Singapore [1, 2, 3]. The malware was designed for installation on Android devices, allowing the syndicate to remotely access victims’ phones and banking applications [1, 2, 3].

Between February and April 2023, Lau operated the Kuala Lumpur office where he also trained syndicate members on how to use the malware [1, 2, 3]. From May to October 2023, he funded at least five servers located in Malaysia and Hong Kong that hosted the malicious software [1, 2, 3].

From June 2023 until June 2024, the syndicate used the malware to infiltrate victims’ mobile banking apps and steal over S$3.19 million from at least 129 Singapore residents [1, 2, 3].

Lau was arrested on June 12, 2024, outside his home in Muar through a joint operation by the Royal Malaysian Police and Singapore’s Criminal Investigation Department tech crime bureau [1, 2, 3]. He was escorted back to Singapore two days later and has been held in remand since [1, 2, 3].

The prosecution said the syndicate’s operations would have been “dead in the water” without Lau’s payments for the server hosting services [1].

Lau was employed by Taiwanese fugitive Lee Rong Teng, who remains on the run [1, 2, 3]. The syndicate’s office Lau maintained was critical to their scam activities and money theft operations over 2023 and 2024 [1, 2, 3].