Full Report
How we almost got rich
Analysis Summary
# Incident Report: The "How We Almost Got Rich" Scams
## Executive Summary
This report details an extensive fraudulent investment ecosystem targeting individuals through fake cryptocurrency and stock trading platforms. Using a combination of aggressive social engineering, fake "personal account managers," and sophisticated web templates, threat actors successfully siphoned funds from victims under the guise of high-yield investments. The operation was ultimately disrupted through digital risk protection measures and the identification of a large network of interconnected fraudulent domains.
## Incident Details
- **Discovery Date:** Not explicitly stated (Ongoing research)
- **Incident Date:** Active campaign observed throughout 2023-2024
- **Affected Organization:** Multiple impersonated financial brands and individual victims
- **Sector:** Finance / Cryptocurrency / Retail Investing
- **Geography:** Global (with significant focus on European and Asian investors)
## Timeline of Events
### Initial Access
- **Date/Time:** Varying (Campaign duration)
- **Vector:** Malicious Advertisements (Malvertising) and Social Media Phishing
- **Details:** Victims were lured via social media ads promising high returns on investments or using celebrity deepfakes/impersonations to build trust.
### Lateral Movement
- **Details:** In this context, lateral movement refers to the attackers moving the victim from public platforms (Social Media) to private communication channels (WhatsApp/Telegram) to establish a "personal" relationship.
### Data Exfiltration/Impact
- **Details:** Direct theft of financial assets. Victims were persuaded to deposit funds into "investment accounts" controlled by the attackers. Additionally, victims' PII (Personally Identifiable Information) was collected during "KYC" processes on fake sites.
### Detection & Response
- **How it was discovered:** Group-IB's Digital Risk Protection (DRP) identified clusters of domains sharing identical infrastructure and source code.
- **Response actions taken:** Domain takedown requests, public awareness reporting, and integration of indicators into Fraud Protection systems.
## Attack Methodology
- **Initial Access:** Social engineering via targeted ads and SEO poisoning.
- **Persistence:** Maintaining contact with victims via encrypted messaging apps (WhatsApp) to prevent them from seeking outside advice.
- **Privilege Escalation:** N/A (Victim-centric fraud).
- **Defense Evasion:** Use of short-lived domains and Cloudflare to hide backend IP addresses; rotating brand names frequently.
- **Credential Access:** Phishing for login credentials via fake trading dashboards.
- **Discovery:** Scammers profile victims during "onboarding" calls to determine their total net worth.
- **Lateral Movement:** Transitioning the victim from a web browser to a high-pressure phone/chat environment.
- **Collection:** Gathering credit card details and identity documents under the guise of "verification."
- **Exfiltration:** Transfer of victim funds to attacker-controlled crypto-wallets or offshore accounts.
- **Impact:** Financial loss and identity theft.
## Impact Assessment
- **Financial:** Total losses estimated in the millions (individual victims reported losses ranging from hundreds to hundreds of thousands of dollars).
- **Data Breach:** Compromise of victim PII, including government IDs and financial statements.
- **Operational:** N/A.
- **Reputational:** Significant damage to the legitimate financial brands being impersonated by the scammers.
## Indicators of Compromise
- **Network Indicators:**
- Multiple domains registered with short lifespans (e.g., `investment-pro-secure[.]com`)
- IP addresses associated with known fraudulent hosting clusters (Defanged: `192[.]0[.]2[.]1`).
- **Behavioral Indicators:**
- High-pressure sales tactics via WhatsApp.
- Requests for remote access (e.g., AnyDesk) to "help" the victim set up their account.
- Guaranteed high returns with "zero risk."
## Response Actions
- **Containment:** Takedown of fraudulent domains and social media accounts.
- **Eradication:** Blocking of attacker-controlled payment gateway IDs where possible.
- **Recovery:** Assisting victims in reporting to local law enforcement and financial institutions.
## Lessons Learned
- **Domain Lifespan:** Fraudulent sites often use very new domains; monitoring for "newly registered domains" is a high-fidelity signal.
- **Social Trust:** Attackers heavily rely on the "Personal Account Manager" trope to bypass a victim's natural skepticism.
- **Infrastructure Sharing:** Scammers often reuse the same backend templates, allowing for bulk identification of fraudulent networks.
## Recommendations
- **For Individuals:** Avoid clicking investment ads on social media; verify brokers via official regulatory registries (e.g., FCA, SEC).
- **For Organizations:** Deploy Digital Risk Protection (DRP) to monitor for brand impersonation and unauthorized use of logos.
- **For Technical Teams:** Implement strict email and web filtering to block access to newly registered domains (less than 30 days old).