Full Report
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime
Analysis Summary
# Incident Report: Coordinated Disruption of Xinbi Guarantee Marketplace
## Executive Summary
The U.S. Department of Justice (DoJ) and the Scam Center Strike Force successfully disrupted "Xinbi Guarantee," a massive illicit Telegram-based marketplace facilitating "pig butchering" scams and money laundering. The operation resulted in the freezing of $52.8 million in cryptocurrency, the seizure of critical Telegram infrastructure, and the dismantling of 13 scam compounds in Madagascar. The marketplace is estimated to have processed over $30 billion in illicit transactions since 2022.
## Incident Details
- **Discovery Date:** Ongoing investigation; specific action announced Wednesday, Sept 9, 2026.
- **Incident Date:** Marketplace active since approximately 2022.
- **Affected Organization:** Various American victims of wire fraud and romance scams; North Korean hackers and sanctioned entities (Prince Group TCO) used the service.
- **Sector:** Cybercrime-as-a-Service (CaaS) / Cryptocurrency / Finance.
- **Geography:** Global operations; scam compounds disrupted in Madagascar; headquarters/leaders linked to Chinese organized crime.
## Timeline of Events
### Initial Access
- **Date/Time:** Circa 2022.
- **Vector:** Social Engineering / Telegram Platform.
- **Details:** Attackers utilized Telegram channels to establish an escrow-style marketplace to connect scam vendors with operators.
### Lateral Movement
- **Infrastructure Expansion:** Following the closure of predecessors *HuiOne* and *Tudou Guarantee*, Xinbi migrated and expanded its reach across Telegram, refusing to comply with initial platform interventions.
### Data Exfiltration/Impact
- **Transaction Volume:** $30 billion processed in total transactions.
- **Financial Loss:** Billions stolen annually from American victims via "pig butchering" (romance) and wire fraud scams.
- **Human Impact:** Solicitation of human trafficking victims to staff overseas scam compounds.
### Detection & Response
- **Investigation:** U.S. Secret Service and Elliptic identified 52 cryptocurrency wallets linked to the network.
- **Response Actions:**
- Seizure of Telegram channels and banning of usernames (e.g., `xinbi`).
- Confiscation of $52.8 million in USDT (Tether) from 52 wallets.
- Sanctions imposed by OFAC against Chinese-language media facilitating the fraud.
- Physical raids on 13 compounds in Madagascar, resulting in ~400 arrests and seizure of 3,200 devices.
## Attack Methodology
- **Initial Access:** Fraudulent solicitation via Telegram and social media ("Pig Butchering").
- **Persistence:** Rapid migration between Telegram usernames and channels to evade platform bans.
- **Privilege Escalation:** Use of organized crime hierarchies to manage vast networks of "scam slaves" and vendors.
- **Defense Evasion:** Use of cryptocurrency (USDT) to mask money laundering; operating in jurisdictions with perceived low law enforcement reach (Madagascar/SE Asia).
- **Credential Access:** Not applicable (Primarily fraud-based).
- **Discovery:** Scammers conduct reconnaissance on victims via social media and dating apps.
- **Lateral Movement:** Transfer of illicit funds across a network of 52+ merchant wallets to obfuscate the paper trail.
- **Collection:** Escrow services (Xinbi) held funds until scam services (e.g., building fake investment sites) were delivered.
- **Exfiltration:** Conversion of victim wire transfers into cryptocurrency.
- **Impact:** Massive financial theft and operational support for sanctioned entities and North Korean state actors.
## Impact Assessment
- **Financial:** $52.8 million frozen in one day; $938 million total restrained by the Strike Force to date.
- **Data Breach:** Compromise of victim personal and financial information through fraudulent investment portals.
- **Operational:** Disruption of 13 physical scam centers and 3,200 electronic devices.
- **Reputational:** Massive loss of trust in Telegram-based commerce; exposure of Chinese organized crime networks.
## Indicators of Compromise
- **Network Indicators:** Telegram channels associated with `xinbi` [defanged: t[.]me/xinbi].
- **File/Asset Indicators:** 52 cryptocurrency wallet addresses (primarily USDT on Ethereum/Tron).
- **Behavioral Indicators:** Escrow-style transactions involving "Guarantee" services for illicit tools; recruitment for "overseas jobs" in Southeast Asia or Africa.
## Response Actions
- **Containment:** Freezing of 52 merchant wallets to stop the flow of capital.
- **Eradication:** Shutdown of the Telegram storefront and banning of associated handles.
- **Recovery:** Ongoing investigation of 3,200 seized devices to identify further victims and perpetrators.
## Lessons Learned
- **Platform Abuse:** Encrypted messaging platforms like Telegram remain the primary hub for CaaS (Cybercrime-as-a-Service).
- **Global Reach:** Scam centers are migrating to new geographies (Madagascar) as Southeast Asian pressure increases.
- **Escrow Reliability:** Criminals utilize sophisticated escrow models (like Xinbi) to build "trust" within the illicit economy.
## Recommendations
- **Platform Monitoring:** Increased cooperation between messaging apps and law enforcement to preemptively flag "Guarantee" (Escrow) marketplaces.
- **Public Awareness:** Educational campaigns regarding "Pig Butchering" and the risks of unsolicited investment advice on social media.
- **Blockchain Analytics:** Continued use of real-time blockchain monitoring to identify and "taint" wallets associated with known escrow services.