Fake investment sites tied to a $187 million network

On 6 November 2025, members of a WhatsApp group were told to buy a NASDAQ listed small cap at 24.79 dollars and hold it for a 29.00 dollar target. The price peaked at 27.87 on 9 December, up 12.4 percent, and that is when the people running the group sold the shares they had positioned in advance. The target was never reached. By February the stock traded at 14.27, down 42 percent from the entry price, and the group members were left holding the losses.

Group-IB documented that trade as part of an investigation into the investment fraud ecosystem, written up by the company's chief executive Dmitry Volkov in the original report. It profiles two operations that run like businesses, and the reason both are so hard to stop is the same: the victim authorises every payment, often over their bank's warnings. At the transaction, there is nothing to refuse. In 2025, investment scams were the largest fraud loss category in both Australia and the United States, roughly 8.7 billion dollars combined, with the Australian share at 837.7 million across more than 481,000 reports.

A stock tip that demands a receipt

Group-IB tracks the first operation as GoldBull, and it runs pump and dump schemes on real, listed stocks. Deepfake advertisements impersonate financial professionals. Deliberately short ad lifespans manufacture urgency. Geo targeted redirects funnel victims into WhatsApp groups run by a head analyst persona, who names a small cap stock, a limit price and a target, and requires proof of purchase. Victims buy through legitimate brokerages, which is why nothing looks wrong. The arithmetic is uncomfortable: two or three groups of a thousand members each generate enough coordinated buying to move a small cap, and 1.5 to 3 million dollars of victim capital per campaign.

The withdrawal that never completes

The second operation, CoinLure, industrialised the fake investment platform. Victims arrive through search optimised content, social advertising or romance scam grooming, then pass through fake registration, fake KYC and trial fund traps into tiered investment plans. Withdrawals are then obstructed by script: minimum balance requirements, tax and insurance fees of 10 to 30 percent of the balance, forced account upgrades, indefinite technical issues, and finally a compliance freeze. When the victim gives up, the same operators come back offering to recover the funds, for an upfront fee.

Scale is the thing that gives them away

Because these operations have to be industrial, they cannot afford to be artisanal, and that is the opening. Infrastructure analysis starting from one confirmed CoinLure platform surfaced 208 domains across 23 shared templates, with the same hosting and the same contact details, and an estimated network revenue of 187 million dollars. The reusable parts (hosting, templates, contact details, wallets, beneficiary accounts, repeating WhatsApp number patterns) are what graph analysis pulls apart. One impersonating advertisement likewise exposed the wider web of fraudulent ads, redirect URLs and analyst personas. Because cash out passes through exchanges that perform KYC, the transfer pattern hands law enforcement a path from stolen funds to identifiable people.

What a bank can actually act on

Group-IB also reports a quieter signal: customers being groomed by fake platforms measurably change how they use their real banking apps before the large transfers start, with unusual session times and altered patterns. Inside a single institution that is noise. Matched against intelligence that a specific network is active against that customer segment, it becomes a warning that arrives before the money moves. Treat the infrastructure, not the payment, as the detection surface, and pivot hard from any single confirmed domain or beneficiary account.

The industry has spent most of its effort at the payment, which is the one place these operations are strongest. Our coverage of a turnkey fake Tesla token scam kit sold for 500 dollars and of the WindRelay card relay combo shows the same shape: the kit, the template and the hosting are reused long before any individual victim is picked.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions