Cybercriminals Sell Verified Bank and Fintech Mule Accounts on Telegram
Key Takeaways Cybercriminals are leveraging Telegram to establish “Mule-as-a-Service” operations, selling verified bank, fintech, and crypto accounts for money laundering. These illicit...
Key Takeaways
- Cybercriminals are leveraging Telegram to establish “Mule-as-a-Service” operations, selling verified bank, fintech, and crypto accounts for money laundering.
- These illicit services mimic legitimate businesses, offering tiered pricing, customer support, and account replacement guarantees.
- Advanced AI tools, including deepfakes and LLMs, are being used to bypass identity verification, automate account “warming,” and evade anti-money laundering (AML) detection.
- Financial institutions face a significant challenge in detecting these sophisticated fraud schemes, necessitating enhanced identity verification and behavioral analytics.
A new wave of organized cybercrime has transformed money laundering into a streamlined, on-demand illicit service, with threat actors openly peddling verified bank accounts, fintech wallets, and cryptocurrency exchange accounts through Telegram channels. This alarming trend is detailed in recent research, which highlights the professionalization of the underground market for financial mule accounts.
Table Of Content
This burgeoning black market has transcended rudimentary recruitment methods, evolving into a sophisticated industry. It now boasts structured pricing models, dedicated customer support, and even guarantees for account replacement should a purchased account be compromised or frozen.
The illicit funds channeled through these networks originate from a variety of cybercriminal activities, including widespread phishing campaigns, devastating ransomware attacks, cunning Business Email Compromise (BEC) scams, and elaborate investment fraud schemes. In the United States alone, it is estimated that a staggering 0.3% of all accounts within financial institutions are controlled by these illicit mule operations, according to a comprehensive report on the subject.
These fraudulent operations exploit stolen identities, AI-generated personas, and compromised credentials to establish accounts that successfully navigate the stringent identity verification processes of traditional banks and modern fintech platforms.
Criminals employ a range of deceptive tactics, including expertly forged documents, realistic deepfake videos, and synthetic identity kits, to onboard new accounts without triggering fraud detection systems. Once activated, these accounts are used to rapidly receive illicit funds, quickly distribute them across multiple financial entities, and withdraw the money before financial institutions can react or intervene. For further details, refer to the full research document on Cybercriminals Use Telegram Channels to Sell Verified Bank and Fintech Mule Accounts.
Analysts at KELA Cyber Intelligence Center have uncovered extensive illicit activity associated with these mule networks. Their investigations span across various platforms, including Telegram channels, dark web forums, and encrypted messaging groups, revealing a robust and interconnected criminal infrastructure.
In a report shared with Cyber Security News (CSN), KELA stated that threat actors are openly advertising a wide array of services and products. This includes verified bank accounts, fintech wallets, cryptocurrency exchange accounts, meticulously forged identity documents, and comprehensive money laundering operations—all operating at an industrial scale. The full report can be found on KELA’s blog.
The Rise of Mule-as-a-Service on Telegram
Telegram has emerged as the primary marketplace for what security researchers term “Mule-as-a-Service” (MaaS). This specialized segment is part of the broader “Fraud-as-a-Service” ecosystem, offering a streamlined approach for criminals seeking to launder illicit funds.
Sellers on these Telegram channels openly advertise accounts from financial institutions across the United States, Latin America, and Europe. Some posts even feature hundreds of accounts for sale, complete with customer testimonials and vouchers to establish their credibility and reliability.
These channels are managed with a surprising level of professionalism, mirroring legitimate e-commerce businesses. They often include comprehensive refund policies, assuring buyers that they will receive a replacement if a purchased account is frozen or restricted, as detailed in the KELA report.
KELA’s analysis specifically identified nearly 250,000 Telegram messages related to Brazilian “Contas Laranja,” or “Orange Accounts.” These are bank accounts either rented or fraudulently created specifically to facilitate the movement of illicit funds through Brazil’s PIX instant payment system.
In Argentina, over 100,000 Telegram messages were found to reference the sale or rental of accounts linked to CBU and CVU identifiers, which are crucial for local banks and digital wallets. Furthermore, Colombian fintech platforms like Nequi and Daviplata were frequently mentioned in underground discussions due to their perceived ease of account onboarding, making them attractive targets for mule operations.
Some sellers offer end-to-end cash-out pipelines, where a buyer can transfer “dirty” funds and receive “clean” money in return. For instance, an actor on the Russian-origin Telegram channel “GrossInfo” was observed selling edited identity documents designed to bypass Know Your Customer (KYC) checks. These sellers also promote PSD document templates engineered to pass automated identity verification, with one such post garnering over 400 replies from interested parties, illustrating the high demand for these tools.
AI’s Role in Evading Detection
The integration of artificial intelligence has fundamentally reshaped the creation and management of mule accounts, making these operations significantly harder to detect. Threat actors are now employing advanced large language models (LLMs), sophisticated deepfake video tools, and platforms like RunwayML to generate highly realistic facial movement videos. These deepfakes are specifically designed to trick remote verification systems used by banks and various fintech applications.
A manual discovered on the CrackedTo forum provided explicit instructions on how to leverage AI. It advised users to prompt ChatGPT with phrases such as “generate natural facial movements for verification” to effectively bypass the liveness checks embedded in banking applications.
Beyond the initial account creation, AI is also being utilized to automate the “account warming” process. In this stage, bots conduct low-risk transactions, such as paying utility bills, to establish a facade of legitimacy for an account before it begins receiving illicit funds. This subtle activity helps the account avoid immediate suspicion.
Furthermore, cybercriminals are deploying predictive smurfing algorithms. These algorithms dynamically adjust transfer sizes and timing to remain below the detection thresholds of Anti-Money Laundering (AML) systems. Voice cloning tools, built on Retrieval-based Voice Conversion (RVC) systems, are also being used to replicate a victim’s voice, enabling threat actors to bypass callback verification protocols at financial institutions.
What You Should Do
- Actively Monitor Threat Intelligence: Financial institutions must continuously monitor dark web forums and Telegram channels for emerging Mule-as-a-Service (MaaS) activities and indicators.
- Upgrade Identity Verification Systems: Implement advanced identity verification technologies capable of detecting deepfake injection attacks, where synthetic video feeds directly into banking application input pipelines.
- Deploy Behavioral Analytics: Utilize behavioral analytics systems designed to recognize AI-assisted account warming patterns and adaptive smurfing behaviors that traditional AML systems may overlook.
- Enhance Fraud Detection: Strengthen existing fraud detection frameworks to identify suspicious transaction patterns indicative of mule account activity, especially those involving rapid fund dispersion.
- Educate Employees: Train employees on the latest tactics used by money mules and the sophisticated methods they employ to bypass security measures.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.