Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Claude Security Adds Mythos 5 for Enhanced Vulnerability Scanning
August 21, 2026
WhatsApp Groups Used for Stock Market Manipulation and Crypto Scams
August 21, 2026
Microsoft Doubles Mailbox Storage to 100 GB for Exchange Online Users
August 21, 2026
Home/CyberSecurity News/WhatsApp Groups Used for Stock Market Manipulation and Crypto Scams
CyberSecurity News

WhatsApp Groups Used for Stock Market Manipulation and Crypto Scams

Key Takeaways Sophisticated fraud networks are leveraging WhatsApp groups to orchestrate stock market manipulation and cryptocurrency scams. These operations, identified as GoldBull and CoinLure,...

Marcus Rodriguez
Marcus Rodriguez
August 21, 2026 5 Min Read
4 0

Key Takeaways

  • Sophisticated fraud networks are leveraging WhatsApp groups to orchestrate stock market manipulation and cryptocurrency scams.
  • These operations, identified as GoldBull and CoinLure, exploit legitimate trading platforms and social engineering to defraud victims.
  • Victims are convinced to make real investments or trades, unknowingly participating in “pump-and-dump” schemes or depositing funds into fake crypto platforms.
  • The scams utilize deepfake advertisements, geo-targeting, and convincing “analyst” personas to build trust and pressure victims into action.
  • Combined, these fraud networks are estimated to generate hundreds of millions in illicit revenue, highlighting the need for vigilance and cross-institutional threat intelligence.

Cybersecurity researchers have uncovered extensive fraud operations utilizing WhatsApp groups to manipulate stock markets and facilitate cryptocurrency scams. These schemes, which do not rely on account hacking but rather on sophisticated social engineering, trick individuals into making real investments that ultimately lead to significant financial losses. The tactics employed range from convincing victims to participate in coordinated “pump-and-dump” stock schemes to luring them onto fraudulent crypto trading platforms.

Table Of Content

  • Key Takeaways
  • WhatsApp Groups Drive Real Stock Pumps
  • Fake Platforms Expand the Network
  • What You Should Do

The core of these campaigns lies in persuading individuals to execute legitimate trades through their own brokerages, only for the perpetrators to profit from the resulting market movements, leaving victims with substantial losses once prices inevitably collapse. These operations initiate with compelling, but short-lived, deepfake advertisements and messages promising lucrative stock tips. Individuals who engage with these ads are then geographically filtered and directed into private WhatsApp groups.

Within these groups, a charismatic “head analyst” guides members, providing specific small-cap stock recommendations, target prices, and enticing profit projections. This seemingly expert advice is, in reality, a coordinated effort to manipulate market prices for the benefit of the scammers.

Analysts at Group-IB identified these fraudulent activities during their investigation into two organized investment fraud operations, dubbed GoldBull and CoinLure. Group-IB said in a report, shared with Cyber Security News (CSN), that these types of fraud are particularly challenging to combat because victims willingly authorize the transactions themselves, having been thoroughly groomed by the scammers. The findings underscore a critical challenge: a social engineering scam can exploit trusted applications, brokerages, and exchanges without direct breaches, highlighting the need for a comprehensive response that extends beyond individual suspicious transactions.

WhatsApp Groups Drive Real Stock Pumps

The GoldBull operation commences with advertisements featuring deepfake impersonations of financial experts. The transient nature of these online advertisements is designed to create a sense of urgency, pressuring potential victims to act swiftly. Subsequently, geo-targeted redirects funnel these individuals into exclusive WhatsApp communities. Here, an “analyst” persona presents what appears to be a unique, time-sensitive investment opportunity.

Group members receive instructions to purchase a specific, genuine small-cap stock via their personal brokerage accounts and are asked to provide proof of their transactions. This collective buying activity generates the necessary volume to artificially inflate the stock’s price. Researchers estimate that just two or three WhatsApp groups, each comprising approximately 1,000 participants, can collectively inject between $1.5 million and $3 million of victim funds into a single campaign, sufficient to significantly impact a thinly traded stock.

In one documented instance, victims were instructed on November 6, 2025, to acquire a NASDAQ-listed share at $24.79, with a projected target price of $29. By December 9, the stock price had risen to $27.87, representing a 12.4% increase. At this peak, the orchestrators of the scheme liquidated their pre-acquired holdings, while the promised $29 target was never achieved. By February, the same share had plummeted to $14.27, a staggering 42% below the victims’ initial purchase price. This sophisticated scam leverages trust and rapid execution, bypassing the need to compromise brokerage accounts directly.

Fusion’s end-state architecture (Source – Group-IB)

Individuals should exercise extreme caution regarding urgent trading advice, celebrity-endorsed advertisements, and chat groups that demand proof of purchase, especially when purported experts guarantee specific returns. These are classic red flags often seen in deepfake investment scam campaigns.

Fake Platforms Expand the Network

The CoinLure operation, a related fraudulent activity, employs a different but equally deceptive strategy. It leverages search engine optimized pages, social media advertisements, and even romance scam tactics to direct victims to counterfeit investment platforms. These platforms often mimic legitimate services, featuring fake registration processes, identity verification steps, and even offering “trial funds” before presenting victims with tiered investment plans. This staged approach is designed to build a false sense of familiarity and legitimacy before demanding larger financial commitments.

When victims attempt to withdraw their funds from these fraudulent platforms, they are met with a litany of excuses. These include demands for minimum balances, purported taxes, or insurance fees ranging from 10% to 30% of their supposed earnings, forced account upgrades, technical “issues,” and eventual “compliance freezes.” In some particularly egregious cases, victims are later contacted with a “recovery offer,” which itself requires yet another upfront fee. It is crucial to remember that no legitimate investment platform will ever demand additional payment simply for a customer to access their own money.

Investigators successfully linked one verified CoinLure platform to an extensive network of 208 domains, all utilizing 23 shared templates, common hosting providers, and identical contact information. This vast infrastructure suggests an estimated network revenue of $187 million. For cybersecurity defenders, this interconnectedness offers a crucial avenue for disruption: identifying one fraudulent page can lead to the exposure of its associated advertisements, redirection mechanisms, and the personas behind them, an approach highly effective against large-scale fake news networks.

What You Should Do

  • Verify Advisers Independently: Always independently research and verify the credentials and legitimacy of any financial adviser or investment group, regardless of how they are introduced.
  • Use Official Channels: Conduct all investment activities through established, official brokerage platforms and their verified communication channels. Avoid making trades or payments based on instructions received via unofficial chat groups.
  • Be Skeptical of Guaranteed Returns: Legitimate investments carry risk. Be highly suspicious of any offer that guarantees high returns with little to no risk, or promises that seem “too good to be true.”
  • Never Pay to Withdraw Funds: A legitimate financial institution will never ask for upfront fees, taxes, or “insurance” payments to release your own money. Any such request is a definitive sign of a scam.
  • Monitor Account Activity: Regularly review your financial accounts for any unusual activity or unauthorized transactions.
  • Report Suspicious Activity: If you encounter deepfake advertisements, suspicious investment offers, or are invited to questionable investment groups, report them to relevant authorities and the platform providers (e.g., WhatsApp, social media networks).

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitSecurity

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Microsoft Doubles Mailbox Storage to 100 GB for Exchange Online Users

Next Post

Claude Security Adds Mythos 5 for Enhanced Vulnerability Scanning

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical GitLab Code Injection Flaw CVE-2023-5006 Actively Exploited
August 21, 2026
Critical WordPress Plugin Bug Exposes Sites to Remote Code Execution
August 21, 2026
Claude Opus 5 AI Bypasses Obfuscated Binaries, Not Defeats Them
August 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us