Full Report
Group-IB’s Threat Intelligence Report on a Singapore-Targeted Scam Operation
Analysis Summary
# Incident Report: "Immediate Era" Investment Scam Operation
## Executive Summary
The "Immediate Era" is a large-scale fraudulent investment operation targeting Singaporean citizens through sophisticated social engineering and brand impersonation. The attackers utilize deepfake videos of Singaporean political figures and fraudulent Google Ads to lure victims into a fake trading platform designed to exfiltrate personal data and financial deposits. The operation is characterized by its high level of persistence and the use of aggressive telemarketing to pressure victims after initial data collection.
## Incident Details
- **Discovery Date:** August 2024 (Group-IB Report Publication)
- **Incident Date:** Ongoing operation identified in 2024
- **Affected Organization:** Customers of various Singaporean financial institutions; impersonation of Singaporean Government/News outlets
- **Sector:** Financial Services / Retail Customers
- **Geography:** Singapore (Primary Target)
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing
- **Vector:** Malicious Advertising (Malvertising) and Social Engineering.
- **Details:** Attackers deploy paid Google Ads across Search, YouTube, and Gmail. These ads feature deepfake videos or fabricated endorsements from well-known Singaporean political figures promising high-yield investment returns.
### Lateral Movement
- **Details:** Not applicable in the traditional network sense; however, the attack "moves" the victim through a series of redirected landing pages (evasion chain) to reach the final fraudulent registration portal.
### Data Exfiltration/Impact
- **Details:** Victims submit full names, email addresses, and phone numbers via registration forms. Once registered, victims are pressured to deposit funds into controlled fraudulent accounts.
### Detection & Response
- **How it was discovered:** Identified by Group-IB Threat Intelligence through monitoring of fraudulent domains and deepfake trends targeting the APAC region.
- **Response actions taken:** Analysis of the redirect infrastructure, reporting of malicious domains, and issuance of public advisories to warn potential victims.
## Attack Methodology
- **Initial Access:** Malvertising via Google Ads and social media promotions.
- **Persistence:** Aggressive follow-up via phone calls and emails once contact information is harvested.
- **Privilege Escalation:** N/A (Focused on victim deception rather than system exploitation).
- **Defense Evasion:** Use of multiple redirect pages to bypass automated ad-security scanners; use of look-alike domains (typosquatting).
- **Credential Access:** Harvesting of personal identity information (PII) via fake registration forms.
- **Discovery:** Scammers use scraped public data to target Singaporean demographics specifically.
- **Lateral Movement:** N/A.
- **Collection:** Gathering victim financial capacity details through "consultation" calls.
- **Exfiltration:** Direct transfer of victim funds to scammer-controlled bank accounts/wallets.
- **Impact:** Financial loss for individuals and reputational damage to impersonated government officials.
## Impact Assessment
- **Financial:** Significant potential losses per victim; typical "low-bar" entry deposits followed by aggressive "upselling."
- **Data Breach:** High volume of PII (Names, Emails, Phone numbers) collected.
- **Operational:** N/A.
- **Reputational:** High impact on the integrity of Singaporean political figures and news organizations used in deepfakes.
## Indicators of Compromise
- **Network Indicators:**
- immediate-era[.]com (Defanged)
- immediate-platform[.]net (Defanged)
- Various domains mimicking Singaporean news outlets (e.g., straitstimes-news[.]top - Defanged)
- **Behavioral Indicators:**
- Unsolicited investment advice from "account managers" via phone.
- Difficulty or administrative "loops" when attempting to withdraw funds.
## Response Actions
- **Containment:** Reporting fraudulent ads to Google and social media platforms for removal.
- **Eradication:** Taking down phishing domains through domain registrars.
- **Recovery:** Public awareness campaigns and advisories for victims to contact their banks and local authorities (Singapore Police Force).
## Lessons Learned
- **Deepfake Sophistication:** Scammers are successfully leveraging AI-generated content to bypass the "skepticism barrier" of users.
- **Ad-Platform Abuse:** Large-scale ad platforms remain a primary vector for targeting specific geographic demographics.
- **Redirect Evasion:** The use of intermediate "hop" domains effectively delays the detection of the final malicious landing page by automated crawlers.
## Recommendations
- **Verify Sources:** Always verify investment opportunities through the MAS (Monetary Authority of Singapore) Investor Alert List.
- **Technical Controls:** Implement and encourage the use of ad-blockers and anti-phishing browser extensions.
- **Zero Trust Communication:** Treat all "guaranteed return" investment opportunities contacted via phone or social media as high-risk/fraudulent.
- **Education:** Conduct regular awareness training on identifying deepfake audio/video artifacts.