WhatsApp Groups Used for Stock Market Manipulation and Crypto Scams
Key Takeaways Sophisticated fraud networks are leveraging WhatsApp groups to orchestrate stock market manipulation and cryptocurrency scams. These operations, identified as GoldBull and CoinLure,...
Key Takeaways
- Sophisticated fraud networks are leveraging WhatsApp groups to orchestrate stock market manipulation and cryptocurrency scams.
- These operations, identified as GoldBull and CoinLure, exploit legitimate trading platforms and social engineering to defraud victims.
- Victims are convinced to make real investments or trades, unknowingly participating in “pump-and-dump” schemes or depositing funds into fake crypto platforms.
- The scams utilize deepfake advertisements, geo-targeting, and convincing “analyst” personas to build trust and pressure victims into action.
- Combined, these fraud networks are estimated to generate hundreds of millions in illicit revenue, highlighting the need for vigilance and cross-institutional threat intelligence.
Cybersecurity researchers have uncovered extensive fraud operations utilizing WhatsApp groups to manipulate stock markets and facilitate cryptocurrency scams. These schemes, which do not rely on account hacking but rather on sophisticated social engineering, trick individuals into making real investments that ultimately lead to significant financial losses. The tactics employed range from convincing victims to participate in coordinated “pump-and-dump” stock schemes to luring them onto fraudulent crypto trading platforms.
Table Of Content
The core of these campaigns lies in persuading individuals to execute legitimate trades through their own brokerages, only for the perpetrators to profit from the resulting market movements, leaving victims with substantial losses once prices inevitably collapse. These operations initiate with compelling, but short-lived, deepfake advertisements and messages promising lucrative stock tips. Individuals who engage with these ads are then geographically filtered and directed into private WhatsApp groups.
Within these groups, a charismatic “head analyst” guides members, providing specific small-cap stock recommendations, target prices, and enticing profit projections. This seemingly expert advice is, in reality, a coordinated effort to manipulate market prices for the benefit of the scammers.
Analysts at Group-IB identified these fraudulent activities during their investigation into two organized investment fraud operations, dubbed GoldBull and CoinLure. Group-IB said in a report, shared with Cyber Security News (CSN), that these types of fraud are particularly challenging to combat because victims willingly authorize the transactions themselves, having been thoroughly groomed by the scammers. The findings underscore a critical challenge: a social engineering scam can exploit trusted applications, brokerages, and exchanges without direct breaches, highlighting the need for a comprehensive response that extends beyond individual suspicious transactions.
WhatsApp Groups Drive Real Stock Pumps
The GoldBull operation commences with advertisements featuring deepfake impersonations of financial experts. The transient nature of these online advertisements is designed to create a sense of urgency, pressuring potential victims to act swiftly. Subsequently, geo-targeted redirects funnel these individuals into exclusive WhatsApp communities. Here, an “analyst” persona presents what appears to be a unique, time-sensitive investment opportunity.
Group members receive instructions to purchase a specific, genuine small-cap stock via their personal brokerage accounts and are asked to provide proof of their transactions. This collective buying activity generates the necessary volume to artificially inflate the stock’s price. Researchers estimate that just two or three WhatsApp groups, each comprising approximately 1,000 participants, can collectively inject between $1.5 million and $3 million of victim funds into a single campaign, sufficient to significantly impact a thinly traded stock.
In one documented instance, victims were instructed on November 6, 2025, to acquire a NASDAQ-listed share at $24.79, with a projected target price of $29. By December 9, the stock price had risen to $27.87, representing a 12.4% increase. At this peak, the orchestrators of the scheme liquidated their pre-acquired holdings, while the promised $29 target was never achieved. By February, the same share had plummeted to $14.27, a staggering 42% below the victims’ initial purchase price. This sophisticated scam leverages trust and rapid execution, bypassing the need to compromise brokerage accounts directly.

Individuals should exercise extreme caution regarding urgent trading advice, celebrity-endorsed advertisements, and chat groups that demand proof of purchase, especially when purported experts guarantee specific returns. These are classic red flags often seen in deepfake investment scam campaigns.
Fake Platforms Expand the Network
The CoinLure operation, a related fraudulent activity, employs a different but equally deceptive strategy. It leverages search engine optimized pages, social media advertisements, and even romance scam tactics to direct victims to counterfeit investment platforms. These platforms often mimic legitimate services, featuring fake registration processes, identity verification steps, and even offering “trial funds” before presenting victims with tiered investment plans. This staged approach is designed to build a false sense of familiarity and legitimacy before demanding larger financial commitments.
When victims attempt to withdraw their funds from these fraudulent platforms, they are met with a litany of excuses. These include demands for minimum balances, purported taxes, or insurance fees ranging from 10% to 30% of their supposed earnings, forced account upgrades, technical “issues,” and eventual “compliance freezes.” In some particularly egregious cases, victims are later contacted with a “recovery offer,” which itself requires yet another upfront fee. It is crucial to remember that no legitimate investment platform will ever demand additional payment simply for a customer to access their own money.
Investigators successfully linked one verified CoinLure platform to an extensive network of 208 domains, all utilizing 23 shared templates, common hosting providers, and identical contact information. This vast infrastructure suggests an estimated network revenue of $187 million. For cybersecurity defenders, this interconnectedness offers a crucial avenue for disruption: identifying one fraudulent page can lead to the exposure of its associated advertisements, redirection mechanisms, and the personas behind them, an approach highly effective against large-scale fake news networks.
What You Should Do
- Verify Advisers Independently: Always independently research and verify the credentials and legitimacy of any financial adviser or investment group, regardless of how they are introduced.
- Use Official Channels: Conduct all investment activities through established, official brokerage platforms and their verified communication channels. Avoid making trades or payments based on instructions received via unofficial chat groups.
- Be Skeptical of Guaranteed Returns: Legitimate investments carry risk. Be highly suspicious of any offer that guarantees high returns with little to no risk, or promises that seem “too good to be true.”
- Never Pay to Withdraw Funds: A legitimate financial institution will never ask for upfront fees, taxes, or “insurance” payments to release your own money. Any such request is a definitive sign of a scam.
- Monitor Account Activity: Regularly review your financial accounts for any unusual activity or unauthorized transactions.
- Report Suspicious Activity: If you encounter deepfake advertisements, suspicious investment offers, or are invited to questionable investment groups, report them to relevant authorities and the platform providers (e.g., WhatsApp, social media networks).
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.