{"id":8242,"date":"2022-11-09T14:23:03","date_gmt":"2022-11-09T22:23:03","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=8242"},"modified":"2024-04-26T13:20:00","modified_gmt":"2024-04-26T20:20:00","slug":"scams-using-fake-celebrity-endorsements-target-eu-countries","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/","title":{"rendered":"Scams Using Fake Celebrity Endorsements Target EU Countries"},"content":{"rendered":"<h3><strong>Author: Stelios Chatzistogias<\/strong><\/h3>\n<p>&nbsp;<\/p>\n<h3>Summary<\/h3>\n<p>This report describes a series of scam campaigns that we have been tracking, in which threat actors compromise social media accounts, redirect victims and solicit their contact information, and then attempt to convince them to deposit funds with fake trading companies. This series of campaigns uses a form of a celebrity endorsed scam, a method first seen in 2020,<sup>1<\/sup> and uses a \u201cMeta\u201d coin theme. The campaigns stand out in terms of the media platforms the actors utilize as well as how they stage their attacks. Specifically, the campaigns use Facebook sponsored ads in combination with fake LinkedIn profiles and multiple domains with the same fake content translated into different languages.<\/p>\n<h3>Background<\/h3>\n<p>Remote working as a result of the global Covid-19 pandemic has significantly changed our daily routines. Many people now spend more time at home or connecting virtually through devices, and the amount of digital advertising conducted through social media platforms has increased to match this trend. All of this has led online fraudsters to take advantage of these changes. According to the Federal Trade Commission,<sup>2<\/sup> the total dollar amount reported as lost to fraud from criminal actors using social media as the contact method in 2021 was $770 million, followed by the use of websites or apps at $554 million, and phone calls at $546 million.<\/p>\n<p>Investment scams have evolved, and the actors have become more advanced in their tactics to convince victims to supply private information and credit card details. The scammers\u2019 techniques can involve compromised social media accounts, redirects via multiple social media platforms, and short-lived, randomly generated domains for landing pages, as is the case with the campaigns we will describe in this report.<\/p>\n<h3>Campaigns Analysis<\/h3>\n<p>The \u201cMeta\u201d coin theme used in these campaigns intentionally conflates two separate services: Facebook\u2019s Meta and Inblock\u2019s Metacoin cryptocurrency. Mark Zuckerberg is rebranding Facebook to Meta<sup>3<\/sup> as part of his strategy to create Metaverse: an AI and virtual reality platform. Separately, the founders of the Hong Kong\u2013based company Inblock created Metacoin: a cryptocurrency that is based on hyperledger technology and that has improved security features based on IBM\u2019s LinuxOne platform.<sup>4<\/sup><\/p>\n<p>Although Metacoin and the Meta services are not related, the scam campaigns in this report use the logo from Facebook\u2019s Metaverse platform and the name Metacoin from Inblock\u2019s cryptocurrency, likely in an attempt to make the delivered web content appear legitimate. The fake \u201cMeta&#8221; coin campaigns have been initialized by a compromised Facebook account under the name SoulCircuit.<sup>5<\/sup> SoulCircuit is actually a group that consists of two DJs\/musicians: Tom Moore and Dan Timcke,<sup>6<\/sup> from the UK.<sup>7<\/sup> Their compromised Facebook profile page has almost 600K followers, and is being used to distribute scam-sponsored ads for the fake \u201cMeta\u201d coin cryptocurrency. Another interesting feature of the campaigns is that the attackers seem to be targeting people from specific countries, namely Greece, Italy, and Spain, based on the languages used in the campaigns and the use of pictures and names of actual prime ministers from those countries.<\/p>\n<p>The campaigns consist of five stages. The actor uses different social media platforms to lure and then redirect the victim, eventually leading them to a short-lived domain that seems to be either fully or partially randomly generated. Once a user shows interest and supplies some initial information (name and mobile phone number), they are again redirected to fake trading websites that present requests for a deposit via a credit card or a transfer from other cryptocurrency accounts.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8243\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/stages-of-the-attack.png\" alt=\"\" width=\"422\" height=\"636\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/stages-of-the-attack.png 422w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/stages-of-the-attack-199x300.png 199w\" sizes=\"auto, (max-width: 422px) 100vw, 422px\" \/><br \/>\nFigure 1: Stages of the attack<\/p>\n<h3>Stage 1: Sponsored Facebook Ads Through SoulCircuit\u2019s Compromised Account<\/h3>\n<p>In the first stage of the attack, the actor places \u201cMeta&#8221; coin ads on SoulCircuit\u2019s Facebook main wall. The screenshot in Figure 2 below is from a campaign targeting Greek-speaking individuals or groups. Some of the obvious signs that the campaign is a scam is the fact that there is no punctuation in capital Greek letters. On the other hand, the fact that the account allegedly has a large number of followers (594k) can lead a user to believe this ad is legit. The image on the right-hand side of Figure 2 shows the caption\u2019s text translated into English. Upon clicking the <b>Learn more<\/b> button, a user is redirected to a LinkedIn page, which we consider Stage 2.<\/p>\n<table>\n<tbody>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8244\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-2-original-text-greek.png\" alt=\"\" width=\"884\" height=\"720\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-2-original-text-greek.png 884w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-2-original-text-greek-300x244.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-2-original-text-greek-768x626.png 768w\" sizes=\"auto, (max-width: 884px) 100vw, 884px\" \/><\/td>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8245\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-2-translated-text-english.png\" alt=\"\" width=\"911\" height=\"722\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-2-translated-text-english.png 911w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-2-translated-text-english-300x238.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-2-translated-text-english-768x609.png 768w\" sizes=\"auto, (max-width: 911px) 100vw, 911px\" \/><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\">Original text (Greek)<\/td>\n<td style=\"text-align: center;\">Translated text (English)<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">Figure 2: Sponsored ad in original and English translated text<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Stage 2 &#8211; LinkedIn Posts<\/h3>\n<p>Clicking the Learn More button opens a LinkedIn page that claims that this new cryptocurrency was invented by Meta and presents fake reviews on it (Figures 3 through 5 below), allegedly made by the Prime Minister of Greece Konstantinos Mitsotakis and other famous Greek individuals.<\/p>\n<table>\n<tbody>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8246\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-3a-original-text-greek.png\" alt=\"\" width=\"460\" height=\"724\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-3a-original-text-greek.png 460w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-3a-original-text-greek-191x300.png 191w\" sizes=\"auto, (max-width: 460px) 100vw, 460px\" \/><\/td>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8247\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-3b-translated-text-english.png\" alt=\"\" width=\"467\" height=\"728\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-3b-translated-text-english.png 467w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-3b-translated-text-english-192x300.png 192w\" sizes=\"auto, (max-width: 467px) 100vw, 467px\" \/><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\">Original text (Greek)<\/td>\n<td style=\"text-align: center;\">Translated text (English)<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">Figure 3: Fake article about \u201cMeta\u201d coin in Greek and English<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table>\n<tbody>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8252\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-4a-original-text-greek.png\" alt=\"\" width=\"474\" height=\"731\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-4a-original-text-greek.png 474w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-4a-original-text-greek-195x300.png 195w\" sizes=\"auto, (max-width: 474px) 100vw, 474px\" \/><\/td>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8251\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-4b-translated-text-english.png\" alt=\"\" width=\"482\" height=\"725\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-4b-translated-text-english.png 482w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-4b-translated-text-english-199x300.png 199w\" sizes=\"auto, (max-width: 482px) 100vw, 482px\" \/><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\">Original text (Greek)<\/td>\n<td style=\"text-align: center;\">Translated text (English)<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">Figure 4: Altered photo of the Greek Prime Minister with Mark Zukerberg<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table>\n<tbody>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8249\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-5a-original-text-greek.png\" alt=\"\" width=\"436\" height=\"724\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-5a-original-text-greek.png 436w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-5a-original-text-greek-181x300.png 181w\" sizes=\"auto, (max-width: 436px) 100vw, 436px\" \/><\/td>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8250\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-5b-translated-text-english.png\" alt=\"\" width=\"429\" height=\"722\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-5b-translated-text-english.png 429w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-5b-translated-text-english-178x300.png 178w\" sizes=\"auto, (max-width: 429px) 100vw, 429px\" \/><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\">Original text (Greek)<\/td>\n<td style=\"text-align: center;\">Translated text (English)<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">Figure 5: Unrelated photo of Yannis Stournaras: a Greek economist who has been the Governor of the Bank of Greece since June 2014<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The LinkedIn profile that posted the fake article about \u201cMeta\u201d coin belongs to a \u201cRachelle Young\u201d (Figure 6 below), who appears to be a financial analyst from the U.S. State of Colorado and whose profile has more than 500 connections. The recent activity is relevant and of interest because the profile\u2019s owner has posted the same article translated into the same three different languages.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8253\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-6-a-fake-linkedin-profile-posting-the-same-meta-coin-article-in-multiple-languages.png\" alt=\"\" width=\"552\" height=\"901\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-6-a-fake-linkedin-profile-posting-the-same-meta-coin-article-in-multiple-languages.png 552w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-6-a-fake-linkedin-profile-posting-the-same-meta-coin-article-in-multiple-languages-184x300.png 184w\" sizes=\"auto, (max-width: 552px) 100vw, 552px\" \/><br \/>\nFigure 6: A fake LinkedIn profile posting the same \u201cMeta\u201d coin article in multiple languages<\/p>\n<p>The activity tab on her profile shows that this activity has been going on for weeks.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8254\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-7-continuous-linkedin-activity.png\" alt=\"\" width=\"430\" height=\"901\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-7-continuous-linkedin-activity.png 430w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-7-continuous-linkedin-activity-143x300.png 143w\" sizes=\"auto, (max-width: 430px) 100vw, 430px\" \/><br \/>\nFigure 7: Continuous LinkedIn activity<\/p>\n<p>The actor has posted articles in languages besides Greek and has used photos and stories tailored to those other countries. For example, the screenshots below show altered photos and narratives allegedly relating to Mario Draghi (an Italian public official) and Dietrich Mateschitz (an Austrian businessman).<\/p>\n<table>\n<tbody>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8255\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-8-meta-coin-scam-campaign-targeting-italy.png\" alt=\"\" width=\"588\" height=\"901\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-8-meta-coin-scam-campaign-targeting-italy.png 588w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-8-meta-coin-scam-campaign-targeting-italy-196x300.png 196w\" sizes=\"auto, (max-width: 588px) 100vw, 588px\" \/><\/td>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8257\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-9-meta-coin-scam-campaign-targeting-germany.png\" alt=\"\" width=\"530\" height=\"901\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-9-meta-coin-scam-campaign-targeting-germany.png 530w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-9-meta-coin-scam-campaign-targeting-germany-176x300.png 176w\" sizes=\"auto, (max-width: 530px) 100vw, 530px\" \/><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\">Figure 8: \u201cMeta\u201d coin scam campaign targeting Italy<\/td>\n<td style=\"text-align: center;\">Figure 9: \u201cMeta\u201d coin scam campaign targeting Germany<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Stage 3 &#8211; Landing Pages and Randomly Generated Domains<\/h3>\n<p>These fake news articles contain links to two different domains that have the same content, including design and graphs, but they are in two different languages, as shown in Figures 10 and 11 below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8259\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-10-altered-youtube-image-that-points-to-scam-website.png\" alt=\"\" width=\"1920\" height=\"691\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-10-altered-youtube-image-that-points-to-scam-website.png 1920w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-10-altered-youtube-image-that-points-to-scam-website-300x108.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-10-altered-youtube-image-that-points-to-scam-website-1024x369.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-10-altered-youtube-image-that-points-to-scam-website-768x276.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-10-altered-youtube-image-that-points-to-scam-website-1536x553.png 1536w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><br \/>\nFigure 10: Altered YouTube image that points to scam website<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8258\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-11-altered-youtube-image-that-points-to-scam-website.png\" alt=\"\" width=\"1920\" height=\"450\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-11-altered-youtube-image-that-points-to-scam-website.png 1920w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-11-altered-youtube-image-that-points-to-scam-website-300x70.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-11-altered-youtube-image-that-points-to-scam-website-1024x240.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-11-altered-youtube-image-that-points-to-scam-website-768x180.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-11-altered-youtube-image-that-points-to-scam-website-1536x360.png 1536w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><br \/>\nFigure 11: Altered YouTube image that points to scam website<\/p>\n<p>The scam websites embedded in the code of the YouTube images above, are 365coinmode and 365graphiccoin. Both sites host the same page translated into different languages, which is shown in Figures 12 and 13 below. Following them, Figure 14 shows the English language version.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8261\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-12-landing-page-on-365coinmodecom-in-greek.png\" alt=\"\" width=\"1841\" height=\"825\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-12-landing-page-on-365coinmodecom-in-greek.png 1841w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-12-landing-page-on-365coinmodecom-in-greek-300x134.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-12-landing-page-on-365coinmodecom-in-greek-1024x459.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-12-landing-page-on-365coinmodecom-in-greek-768x344.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-12-landing-page-on-365coinmodecom-in-greek-1536x688.png 1536w\" sizes=\"auto, (max-width: 1841px) 100vw, 1841px\" \/><br \/>\nFigure 12: Landing page on 365coinmode[.]com, in Greek<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8260\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-13-landing-page-on-365graphiccoincom-in-italian.png\" alt=\"\" width=\"1844\" height=\"819\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-13-landing-page-on-365graphiccoincom-in-italian.png 1844w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-13-landing-page-on-365graphiccoincom-in-italian-300x133.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-13-landing-page-on-365graphiccoincom-in-italian-1024x455.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-13-landing-page-on-365graphiccoincom-in-italian-768x341.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-13-landing-page-on-365graphiccoincom-in-italian-1536x682.png 1536w\" sizes=\"auto, (max-width: 1844px) 100vw, 1844px\" \/><br \/>\nFigure 13: Landing page on 365graphiccoin[.]com, in Italian<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8262\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-14-landing-page-on-365graphiccoincom-in-english.png\" alt=\"\" width=\"1844\" height=\"821\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-14-landing-page-on-365graphiccoincom-in-english.png 1844w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-14-landing-page-on-365graphiccoincom-in-english-300x134.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-14-landing-page-on-365graphiccoincom-in-english-1024x456.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-14-landing-page-on-365graphiccoincom-in-english-768x342.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-14-landing-page-on-365graphiccoincom-in-english-1536x684.png 1536w\" sizes=\"auto, (max-width: 1844px) 100vw, 1844px\" \/><br \/>\nFigure 14: Landing page on 365graphiccoin[.]com, in English<\/p>\n<h3>Stage 4: Personal Information Gathering<\/h3>\n<p>The goal of this particular stage of the campaigns is not to steal any credit card details, but instead to have the victims complete a form with their names and phone numbers. The victims then get redirected to fake trading company websites, such as spartan-trade[.]com and networkfsi[.]com, which ask the victims to make financial deposits. Reports from Greece and the U.K. indicate that the actors use the contact information the victims provided to get in touch with them if they do not make the deposit as requested, in the next stage of the attack, described below.8,9 The scammers try to convince the victims that the campaign is being conducted by a legitimate investment company.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8263\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-15a-original-text-greek.png\" alt=\"\" width=\"1363\" height=\"496\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-15a-original-text-greek.png 1363w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-15a-original-text-greek-300x109.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-15a-original-text-greek-1024x373.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-15a-original-text-greek-768x279.png 768w\" sizes=\"auto, (max-width: 1363px) 100vw, 1363px\" \/><br \/>\nOriginal text (Greek)<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8264\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-15b-translated-text-english.png\" alt=\"\" width=\"1353\" height=\"491\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-15b-translated-text-english.png 1353w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-15b-translated-text-english-300x109.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-15b-translated-text-english-1024x372.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-15b-translated-text-english-768x279.png 768w\" sizes=\"auto, (max-width: 1353px) 100vw, 1353px\" \/><br \/>\nTranslated text (English)<\/p>\n<p>Figure 15: A form for creating a fake account for \u201cMeta\u201d coin<\/p>\n<h3>Stage 5: Money theft<\/h3>\n<p>After providing personal details, a victim gets redirected to a fake but visually appealing website. In our tests, we were redirected to Spartan Trading, a fake trading website. It was registered on 5 July 2022 and contains the aforementioned deposit page where a victim is asked to choose an amount of money to deposit. As of this writing, the available payment options are cryptocurrencies and credit cards. The screenshots below illustrate how the cryptocurrency payment system works.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8265\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-16-fake-trading-website.png\" alt=\"\" width=\"1920\" height=\"855\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-16-fake-trading-website.png 1920w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-16-fake-trading-website-300x134.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-16-fake-trading-website-1024x456.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-16-fake-trading-website-768x342.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-16-fake-trading-website-1536x684.png 1536w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><br \/>\nFigure 16: Fake trading website<\/p>\n<table>\n<tbody>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8266\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-17a.png\" alt=\"\" width=\"1161\" height=\"861\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17a.png 1161w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17a-300x222.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17a-1024x759.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17a-768x570.png 768w\" sizes=\"auto, (max-width: 1161px) 100vw, 1161px\" \/><\/td>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8267\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-17b.png\" alt=\"\" width=\"938\" height=\"901\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17b.png 938w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17b-300x288.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17b-768x738.png 768w\" sizes=\"auto, (max-width: 938px) 100vw, 938px\" \/><\/td>\n<td><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8268\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/fig-17c.png\" alt=\"\" width=\"1069\" height=\"890\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17c.png 1069w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17c-300x250.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17c-1024x853.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/fig-17c-768x639.png 768w\" sizes=\"auto, (max-width: 1069px) 100vw, 1069px\" \/><\/td>\n<\/tr>\n<tr>\n<td style=\"text-align: center;\">Client portal landing page<\/td>\n<td style=\"text-align: center;\">Payment choices<\/td>\n<td style=\"text-align: center;\">Crypto wallet for depositing crypto<\/td>\n<\/tr>\n<tr>\n<td colspan=\"3\">Figure 17: Deposit process for cryptocurrencies<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The screenshots in Figures 18 through 21 below show the credit card payment system on the scam website.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8272\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-18-ipasspay-option.png\" alt=\"\" width=\"1594\" height=\"901\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-18-ipasspay-option.png 1594w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-18-ipasspay-option-300x170.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-18-ipasspay-option-1024x579.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-18-ipasspay-option-768x434.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-18-ipasspay-option-1536x868.png 1536w\" sizes=\"auto, (max-width: 1594px) 100vw, 1594px\" \/><br \/>\nFigure 18: IpassPay option<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8271\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-19-deposit-page.png\" alt=\"\" width=\"1213\" height=\"649\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-19-deposit-page.png 1213w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-19-deposit-page-300x161.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-19-deposit-page-1024x548.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-19-deposit-page-768x411.png 768w\" sizes=\"auto, (max-width: 1213px) 100vw, 1213px\" \/><br \/>\nFigure 19: Deposit page<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8270\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-20-billing-info.png\" alt=\"\" width=\"1222\" height=\"620\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-20-billing-info.png 1222w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-20-billing-info-300x152.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-20-billing-info-1024x520.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-20-billing-info-768x390.png 768w\" sizes=\"auto, (max-width: 1222px) 100vw, 1222px\" \/><br \/>\nFigure 20: Billing Info<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8269\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-21-credit-card-detail-request-page.png\" alt=\"\" width=\"1211\" height=\"602\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-21-credit-card-detail-request-page.png 1211w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-21-credit-card-detail-request-page-300x149.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-21-credit-card-detail-request-page-1024x509.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-21-credit-card-detail-request-page-768x382.png 768w\" sizes=\"auto, (max-width: 1211px) 100vw, 1211px\" \/><br \/>\nFigure 21: Credit card detail request page<\/p>\n<h3>Domain Analysis<\/h3>\n<p>All domains that serve the landing pages are registered to Namecheap and resolve to the same IP address, 45[.]63[.]119[.]177, which belongs to Constant Company LLC: a hosting provider that offers global automated cloud infrastructure. In turn, Constant LLC is a parent company for Vultr, which happens to offer free $100 vouchers for using the platform. This arrangement is a springboard for attackers who have automation in place to deploy and set up scam domains and to operate them cost-free. The screenshots in Figures 22 and 23 below show the landing pages belonging to Constant and Vultr, that are used to advertise their automated cloud infrastructure and the $100 promotion for new users.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8274\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-22-constant-llcs-landing-page.png\" alt=\"\" width=\"1920\" height=\"737\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-22-constant-llcs-landing-page.png 1920w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-22-constant-llcs-landing-page-300x115.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-22-constant-llcs-landing-page-1024x393.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-22-constant-llcs-landing-page-768x295.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-22-constant-llcs-landing-page-1536x590.png 1536w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><br \/>\nFigure 22: Constant LLC\u2019s landing page<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8273\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/figure-23-vultr-dollar100-promotional-offering.png\" alt=\"\" width=\"811\" height=\"814\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-23-vultr-dollar100-promotional-offering.png 811w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-23-vultr-dollar100-promotional-offering-300x300.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-23-vultr-dollar100-promotional-offering-150x150.png 150w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-23-vultr-dollar100-promotional-offering-768x771.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/figure-23-vultr-dollar100-promotional-offering-75x75.png 75w\" sizes=\"auto, (max-width: 811px) 100vw, 811px\" \/><br \/>\nFigure 23: Vultr $100 promotional offering<\/p>\n<h3>Prevention and Mitigation<\/h3>\n<p>These malvertising scams have the following features in common:<\/p>\n<ul>\n<li>The name of the domain involved in a scam is irrelevant to the scam\u2019s theme.<\/li>\n<li>The text of the initial advertisement on Facebook is automatically translated to several languages.<\/li>\n<li>Typos are easy to spot.<\/li>\n<li>The parties that own the LinkedIn profiles used in the scams claim to be financial advisors.<\/li>\n<li>None of the YouTube videos or links to popular domains redirect to any popular domains.<\/li>\n<li>The faces appearing on the websites are edited or the photos are unrelated and have been taken from other articles.<\/li>\n<li>There is no phone number or address of the company. Often, these scams are set up from abroad.<\/li>\n<\/ul>\n<h3>Indicators of Compromise<\/h3>\n<p>The table below provides a list of the IOCs relevant to our recent findings, which can also be found in our GitHub repository.<sup>10<\/sup><\/p>\n<table>\n<tbody>\n<tr>\n<td>hxxps[:]\/\/www[.]linkedin[.]com\/in\/rachelle-young-2928b63b\/<\/td>\n<td>Fake LinkedIn profile<\/td>\n<\/tr>\n<tr>\n<td>hxxps[:]\/\/www[.]linkedin[.]com\/in\/claire-cameron-61a5b7235\/<\/td>\n<td>Fake LinkedIn profile<\/td>\n<\/tr>\n<tr>\n<td>hxxps[:]\/\/www[.]linkedin[.]com\/in\/melanie-springer-450695235\/<\/td>\n<td>Fake LinkedIn profile<\/td>\n<\/tr>\n<tr>\n<td>21cloudcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>21cloudesk[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>21coincloud[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365actioncoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365amazementcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365amazingcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365amzcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365balancecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365basedcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365bestcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365blessedcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365brandcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365brandedcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365bravecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365buildcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365capcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365certaincoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365codifycoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinaction[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinamazement[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinamazing[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinamz[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinanswer[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinapp[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinbalance[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinbased[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinbest[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinblessed[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinbrand[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinbranded[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinbrave[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinbuild[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coincap[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coincertain[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coincodify[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coincore[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coincurious[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coindeluxe[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coindemand[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coindesk[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coindomain[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coineg[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinenormous[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinexp[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinextra[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinfactory[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinfascinating[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinfeed[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinfinance[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinfresh[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinfreshest[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinfuture[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinfuturistical[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinglobe[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coingold[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coingrand[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coingrande[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coingreat[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coingreatest[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinhub[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinhuge[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinideal[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinimpact[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinimprove[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinimproving[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coininfluence[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coininvest[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coininvestment[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinking[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinlead[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinllux[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinlux[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinluxury[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinmaintain[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinmark[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinmarket[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinmaster[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinmax[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinmeta[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinmnp[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinmode[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinmulti[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinplatin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinpowerful[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinprecious[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinpremise[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinprestige[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinprestigious[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinpriceless[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinpro[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinproduct[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinprofit[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinpromise[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinpropelling[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinrise[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinrising[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinsafe[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinsecured[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinstack[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinstandard[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinsustain[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinsustainable[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365cointeam[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365cointech[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365cointecknet[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365cointop[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365cointp[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365cointrading[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365cointrend[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365cointrendy[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365cointsl[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinunit[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinunited[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinuprise[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinweb[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365coinworld[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365corecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365curiouscoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365deluxecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365demandcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365desiredcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365deskcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365deskmarket[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365domaincoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365egcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365expcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365explorecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365expocoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365extracoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365factorycoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365fascinatingcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365feedcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365freshcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365freshestcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365futurecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365globecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365goldcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365grandcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365grandecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365greatcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365greatestcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365hubcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365hugecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365ideacoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365idealcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365impactcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365improvecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365improvingcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365influencecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365investmentcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365kingcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365leadcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365lluxcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365luxcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365maintaincoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365markcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365marketcap[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365marketcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365marketdesk[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365mastercoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365maxcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365mnpcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365modecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365motratcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365multicoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365nowcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365platincap[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365platincoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365platindesk[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365powercoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365powerfulcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365preciouscoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365premisecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365prestigecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365prestigiouscoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365pricelesscoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365procoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365profitcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365profxmarket[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365promisecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365propellingcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365prospectcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365prosperitycoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365risecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365risingcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365safecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365securedcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365smartcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365stackcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365standardcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365sustainablecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365sustaincoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365teamcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365techcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365tecknetcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365topcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365tpcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365tradecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365tradingcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365trendingcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365trendycoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365tslcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365unitcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365unitedcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365uprisecoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365webcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<tr>\n<td>365worldcoin[.]com<\/td>\n<td>Fake \u201cMeta\u201d coin domain<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Endnotes<\/h3>\n<ol>\n<li><a target=\"_blank\" href=\"https:\/\/blog.confiant.com\/fake-celebrity-endorsed-scam-abuses-ad-tech-to-net-1m-in-one-day-ffe330258e3c\" rel=\"noopener\">https:\/\/blog.confiant.com\/fake-celebrity-endorsed-scam-abuses-ad-tech-to-net-1m-in-one-day-ffe330258e3c<\/a><\/li>\n<li><a target=\"_blank\" href=\"https:\/\/www.ftc.gov\/news-events\/data-visualizations\/data-spotlight\/2022\/01\/social-media-gold-mine-scammers-2021\" rel=\"noopener\">https:\/\/www.ftc.gov\/news-events\/data-visualizations\/data-spotlight\/2022\/01\/social-media-gold-mine-scammers-2021<\/a><\/li>\n<li><a target=\"_blank\" href=\"https:\/\/knowledge.insead.edu\/marketing\/why-facebook-rebranding-itself-meta#:~:text=Mark%20Zuckerberg%2C%20founder%20of%20Facebook,phase%20in%20the%20digital%20world\" rel=\"noopener\">https:\/\/knowledge.insead.edu\/marketing\/why-facebook-rebranding-itself-meta#:~:text=Mark%20Zuckerberg%2C%20founder%20of%20Facebook,phase%20in%20the%20digital%20world<\/a>.\u00a0<\/li>\n<li><a target=\"_blank\" href=\"https:\/\/www.ibm.com\/case-studies\/inblock-blockchain-ibm\" rel=\"noopener\">https:\/\/www.ibm.com\/case-studies\/inblock-blockchain-ibm<\/a><\/li>\n<li><a target=\"_blank\" href=\"https:\/\/www.facebook.com\/SoulCircuitMusic\/\" rel=\"noopener\">https:\/\/www.facebook.com\/SoulCircuitMusic\/<\/a><\/li>\n<li><a target=\"_blank\" href=\"https:\/\/www.discogs.com\/artist\/3961188-SoulCircuit\" rel=\"noopener\">https:\/\/www.discogs.com\/artist\/3961188-SoulCircuit<\/a><\/li>\n<li><a target=\"_blank\" href=\"https:\/\/soundcloud.com\/soulcircuitmusic\" rel=\"noopener\">https:\/\/soundcloud.com\/soulcircuitmusic<\/a><\/li>\n<li><a target=\"_blank\" href=\"https:\/\/www.santander.co.uk\/about-santander\/media-centre\/press-releases\/santander-warns-about-celebrity-endorsed-crypto-scams\" rel=\"noopener\">https:\/\/www.santander.co.uk\/about-santander\/media-centre\/press-releases\/santander-warns-about-celebrity-endorsed-crypto-scams<\/a><\/li>\n<li><a target=\"_blank\" href=\"https:\/\/www.ellinikahoaxes.gr\/2022\/09\/01\/scam-metacoin-cryptocurrency\/\" rel=\"noopener\">https:\/\/www.ellinikahoaxes.gr\/2022\/09\/01\/scam-metacoin-cryptocurrency\/<\/a><\/li>\n<li><a target=\"_blank\" href=\"https:\/\/github.com\/infobloxopen\/threat-intelligence\/tree\/main\/cta_indicators\" rel=\"noopener\">https:\/\/github.com\/infobloxopen\/threat-intelligence\/tree\/main\/cta_indicators<\/a><\/li>\n<\/ol>\n<p>\u00a0 <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Author: Stelios Chatzistogias &nbsp; Summary This report describes a series of scam campaigns that we have been tracking, in which threat actors compromise social media accounts, redirect victims and solicit their contact information, and then attempt to convince them to deposit funds with fake trading companies. This series of campaigns uses a form of a [&hellip;]<\/p>\n","protected":false},"author":397,"featured_media":6721,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[554],"tags":[658,657],"class_list":{"0":"post-8242","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-threat-advisory","8":"tag-cyber-threat-advisory","9":"tag-cyber-threat-intelligence","10":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Scams Using Fake Celebrity Endorsements Target EU Countries | Infoblox<\/title>\n<meta name=\"description\" content=\"This report describes a series of scam campaigns that we have been tracking, in which threat actors compromise social media accounts, redirect victims and solicit their contact information, and then attempt to convince them to deposit funds with fake trading companies.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Scams Using Fake Celebrity Endorsements Target EU Countries\" \/>\n<meta property=\"og:description\" content=\"This report describes a series of scam campaigns that we have been tracking, in which threat actors compromise social media accounts, redirect victims and solicit their contact information, and then attempt to convince them to deposit funds with fake trading companies.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-11-09T22:23:03+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-26T20:20:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/ciu-image-17.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"612\" \/>\n\t<meta property=\"og:image:height\" content=\"339\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Infoblox Threat Intel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Infoblox Threat Intel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"19 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/\"},\"author\":{\"name\":\"Infoblox Threat Intel\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\"},\"headline\":\"Scams Using Fake Celebrity Endorsements Target EU Countries\",\"datePublished\":\"2022-11-09T22:23:03+00:00\",\"dateModified\":\"2024-04-26T20:20:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/\"},\"wordCount\":3000,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/ciu-image-17.jpg\",\"keywords\":[\"Cyber Threat Advisory\",\"Cyber Threat Intelligence\"],\"articleSection\":[\"Cyber Threat Advisory\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/\",\"name\":\"Scams Using Fake Celebrity Endorsements Target EU Countries | Infoblox\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/ciu-image-17.jpg\",\"datePublished\":\"2022-11-09T22:23:03+00:00\",\"dateModified\":\"2024-04-26T20:20:00+00:00\",\"description\":\"This report describes a series of scam campaigns that we have been tracking, in which threat actors compromise social media accounts, redirect victims and solicit their contact information, and then attempt to convince them to deposit funds with fake trading companies.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/ciu-image-17.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/ciu-image-17.jpg\",\"width\":612,\"height\":339,\"caption\":\"close up programmer man hand typing on keyboard laptop for register data system or access password at dark operation room , cyber security concept\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/cyber-threat-advisory\\\/scams-using-fake-celebrity-endorsements-target-eu-countries\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Infoblox Threat Intel\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/threat-intelligence\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Cyber Threat Advisory\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/threat-intelligence\\\/cyber-threat-advisory\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Scams Using Fake Celebrity Endorsements Target EU Countries\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\",\"name\":\"Infoblox Threat Intel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"caption\":\"Infoblox Threat Intel\"},\"description\":\"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/infoblox-threat-intel\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Scams Using Fake Celebrity Endorsements Target EU Countries | Infoblox","description":"This report describes a series of scam campaigns that we have been tracking, in which threat actors compromise social media accounts, redirect victims and solicit their contact information, and then attempt to convince them to deposit funds with fake trading companies.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/","og_locale":"en_US","og_type":"article","og_title":"Scams Using Fake Celebrity Endorsements Target EU Countries","og_description":"This report describes a series of scam campaigns that we have been tracking, in which threat actors compromise social media accounts, redirect victims and solicit their contact information, and then attempt to convince them to deposit funds with fake trading companies.","og_url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/","og_site_name":"Infoblox Blog","article_published_time":"2022-11-09T22:23:03+00:00","article_modified_time":"2024-04-26T20:20:00+00:00","og_image":[{"width":612,"height":339,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/ciu-image-17.jpg","type":"image\/jpeg"}],"author":"Infoblox Threat Intel","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Infoblox Threat Intel","Est. reading time":"19 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/"},"author":{"name":"Infoblox Threat Intel","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae"},"headline":"Scams Using Fake Celebrity Endorsements Target EU Countries","datePublished":"2022-11-09T22:23:03+00:00","dateModified":"2024-04-26T20:20:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/"},"wordCount":3000,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/ciu-image-17.jpg","keywords":["Cyber Threat Advisory","Cyber Threat Intelligence"],"articleSection":["Cyber Threat Advisory"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/","url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/","name":"Scams Using Fake Celebrity Endorsements Target EU Countries | Infoblox","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/ciu-image-17.jpg","datePublished":"2022-11-09T22:23:03+00:00","dateModified":"2024-04-26T20:20:00+00:00","description":"This report describes a series of scam campaigns that we have been tracking, in which threat actors compromise social media accounts, redirect victims and solicit their contact information, and then attempt to convince them to deposit funds with fake trading companies.","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/ciu-image-17.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/ciu-image-17.jpg","width":612,"height":339,"caption":"close up programmer man hand typing on keyboard laptop for register data system or access password at dark operation room , cyber security concept"},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/cyber-threat-advisory\/scams-using-fake-celebrity-endorsements-target-eu-countries\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Infoblox Threat Intel","item":"https:\/\/www.infoblox.com\/blog\/category\/threat-intelligence\/"},{"@type":"ListItem","position":3,"name":"Cyber Threat Advisory","item":"https:\/\/www.infoblox.com\/blog\/category\/threat-intelligence\/cyber-threat-advisory\/"},{"@type":"ListItem","position":4,"name":"Scams Using Fake Celebrity Endorsements Target EU Countries"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae","name":"Infoblox Threat Intel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","caption":"Infoblox Threat Intel"},"description":"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.","url":"https:\/\/www.infoblox.com\/blog\/author\/infoblox-threat-intel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/8242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/397"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=8242"}],"version-history":[{"count":5,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/8242\/revisions"}],"predecessor-version":[{"id":8317,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/8242\/revisions\/8317"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/6721"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=8242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=8242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=8242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}