Find notable cyber news and cases, enriched with sources, timelines, and signals.

Asia cross-border fake crypto and forex investment scam campaign

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A current wave of fake crypto and forex investment scams is stealing funds from victims across Asia, using polished trading platforms to look legitimate. The operation reaches targets through social media and messaging apps and is run by organized cross-border groups that coordinate front-end deception with backend money movement. Shared clues such as reused SSL certificates and identical chatbot systems suggest multiple scam operations are linked.

Related Happenings

Ghost Stadium FIFA World Cup fraud campaign

Campaign
First: 27.05.2026 14:28 Last: 27.05.2026 14:28 Sources 1

About this happening: A **Ghost Stadium** fraud campaign has registered **4,300+ FIFA lookalike domains** and is using **paid Facebook ads** to funnel **2026 FIFA World Cup** fans into phishing and tic...

MENA fake online job ad fraud campaign

Campaign
First: 24.12.2025 17:30 Last: 24.12.2025 17:30 Sources 1

About this happening: A **2025** coordinated fraud campaign used **fake online job ads** to target people across **MENA**, stealing **money** and **personal data** through recruitment lures. The operat...

UNC2891 multi-year ATM fraud campaign against Indonesian banks

Campaign
First: 20.11.2025 18:00 Last: 20.11.2025 18:00 Sources 1

About this happening: UNC2891’s **multi-year ATM fraud campaign** against **two Indonesian banks** has been fully exposed, showing a coordinated cash-out operation that used **money mules**, **cloned c...

Timeline

  1. 28.10.2025 18:45 1 articles · 7mo ago

    Group-IB maps Asia fake investment scam infrastructure

    Technical Analysis Update

    Group-IB’s High-Tech Crime Investigation team reports a surge in fake investment platforms imitating cryptocurrency and forex exchanges across Asia, with victims lured through social media and messaging apps and scams run by organized cross-border groups using polished trading interfaces and complex backend systems. The analysis highlights shared technical fingerprints, including reused SSL certificates and identical chatbot systems, and outlines the Victim Manipulation Flow and Multi-Actor Fraud Network models to show how operators build trust, coordinate roles, and launder stolen assets. The team recommends that banks, regulators and cybersecurity teams monitor reused infrastructure components and strengthen Know Your Customer (KYC) controls to block fraudulent accounts.

    Show sources