Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Home/Threats/Cybercriminals Sell Verified Bank and Fintech Mule Accounts on Telegram
Threats

Cybercriminals Sell Verified Bank and Fintech Mule Accounts on Telegram

Key Takeaways Cybercriminals are leveraging Telegram to establish “Mule-as-a-Service” operations, selling verified bank, fintech, and crypto accounts for money laundering. These illicit...

Sarah simpson
Sarah simpson
May 25, 2026 5 Min Read
67 0

Key Takeaways

  • Cybercriminals are leveraging Telegram to establish “Mule-as-a-Service” operations, selling verified bank, fintech, and crypto accounts for money laundering.
  • These illicit services mimic legitimate businesses, offering tiered pricing, customer support, and account replacement guarantees.
  • Advanced AI tools, including deepfakes and LLMs, are being used to bypass identity verification, automate account “warming,” and evade anti-money laundering (AML) detection.
  • Financial institutions face a significant challenge in detecting these sophisticated fraud schemes, necessitating enhanced identity verification and behavioral analytics.

A new wave of organized cybercrime has transformed money laundering into a streamlined, on-demand illicit service, with threat actors openly peddling verified bank accounts, fintech wallets, and cryptocurrency exchange accounts through Telegram channels. This alarming trend is detailed in recent research, which highlights the professionalization of the underground market for financial mule accounts.

Table Of Content

  • Key Takeaways
  • The Rise of Mule-as-a-Service on Telegram
  • AI’s Role in Evading Detection
  • What You Should Do

This burgeoning black market has transcended rudimentary recruitment methods, evolving into a sophisticated industry. It now boasts structured pricing models, dedicated customer support, and even guarantees for account replacement should a purchased account be compromised or frozen.

The illicit funds channeled through these networks originate from a variety of cybercriminal activities, including widespread phishing campaigns, devastating ransomware attacks, cunning Business Email Compromise (BEC) scams, and elaborate investment fraud schemes. In the United States alone, it is estimated that a staggering 0.3% of all accounts within financial institutions are controlled by these illicit mule operations, according to a comprehensive report on the subject.

These fraudulent operations exploit stolen identities, AI-generated personas, and compromised credentials to establish accounts that successfully navigate the stringent identity verification processes of traditional banks and modern fintech platforms.

Criminals employ a range of deceptive tactics, including expertly forged documents, realistic deepfake videos, and synthetic identity kits, to onboard new accounts without triggering fraud detection systems. Once activated, these accounts are used to rapidly receive illicit funds, quickly distribute them across multiple financial entities, and withdraw the money before financial institutions can react or intervene. For further details, refer to the full research document on Cybercriminals Use Telegram Channels to Sell Verified Bank and Fintech Mule Accounts.

Analysts at KELA Cyber Intelligence Center have uncovered extensive illicit activity associated with these mule networks. Their investigations span across various platforms, including Telegram channels, dark web forums, and encrypted messaging groups, revealing a robust and interconnected criminal infrastructure.

In a report shared with Cyber Security News (CSN), KELA stated that threat actors are openly advertising a wide array of services and products. This includes verified bank accounts, fintech wallets, cryptocurrency exchange accounts, meticulously forged identity documents, and comprehensive money laundering operations—all operating at an industrial scale. The full report can be found on KELA’s blog.

The Rise of Mule-as-a-Service on Telegram

Telegram has emerged as the primary marketplace for what security researchers term “Mule-as-a-Service” (MaaS). This specialized segment is part of the broader “Fraud-as-a-Service” ecosystem, offering a streamlined approach for criminals seeking to launder illicit funds.

Sellers on these Telegram channels openly advertise accounts from financial institutions across the United States, Latin America, and Europe. Some posts even feature hundreds of accounts for sale, complete with customer testimonials and vouchers to establish their credibility and reliability.

These channels are managed with a surprising level of professionalism, mirroring legitimate e-commerce businesses. They often include comprehensive refund policies, assuring buyers that they will receive a replacement if a purchased account is frozen or restricted, as detailed in the KELA report.

KELA’s analysis specifically identified nearly 250,000 Telegram messages related to Brazilian “Contas Laranja,” or “Orange Accounts.” These are bank accounts either rented or fraudulently created specifically to facilitate the movement of illicit funds through Brazil’s PIX instant payment system.

In Argentina, over 100,000 Telegram messages were found to reference the sale or rental of accounts linked to CBU and CVU identifiers, which are crucial for local banks and digital wallets. Furthermore, Colombian fintech platforms like Nequi and Daviplata were frequently mentioned in underground discussions due to their perceived ease of account onboarding, making them attractive targets for mule operations.

Some sellers offer end-to-end cash-out pipelines, where a buyer can transfer “dirty” funds and receive “clean” money in return. For instance, an actor on the Russian-origin Telegram channel “GrossInfo” was observed selling edited identity documents designed to bypass Know Your Customer (KYC) checks. These sellers also promote PSD document templates engineered to pass automated identity verification, with one such post garnering over 400 replies from interested parties, illustrating the high demand for these tools.

AI’s Role in Evading Detection

The integration of artificial intelligence has fundamentally reshaped the creation and management of mule accounts, making these operations significantly harder to detect. Threat actors are now employing advanced large language models (LLMs), sophisticated deepfake video tools, and platforms like RunwayML to generate highly realistic facial movement videos. These deepfakes are specifically designed to trick remote verification systems used by banks and various fintech applications.

A manual discovered on the CrackedTo forum provided explicit instructions on how to leverage AI. It advised users to prompt ChatGPT with phrases such as “generate natural facial movements for verification” to effectively bypass the liveness checks embedded in banking applications.

Beyond the initial account creation, AI is also being utilized to automate the “account warming” process. In this stage, bots conduct low-risk transactions, such as paying utility bills, to establish a facade of legitimacy for an account before it begins receiving illicit funds. This subtle activity helps the account avoid immediate suspicion.

Furthermore, cybercriminals are deploying predictive smurfing algorithms. These algorithms dynamically adjust transfer sizes and timing to remain below the detection thresholds of Anti-Money Laundering (AML) systems. Voice cloning tools, built on Retrieval-based Voice Conversion (RVC) systems, are also being used to replicate a victim’s voice, enabling threat actors to bypass callback verification protocols at financial institutions.

What You Should Do

  • Actively Monitor Threat Intelligence: Financial institutions must continuously monitor dark web forums and Telegram channels for emerging Mule-as-a-Service (MaaS) activities and indicators.
  • Upgrade Identity Verification Systems: Implement advanced identity verification technologies capable of detecting deepfake injection attacks, where synthetic video feeds directly into banking application input pipelines.
  • Deploy Behavioral Analytics: Utilize behavioral analytics systems designed to recognize AI-assisted account warming patterns and adaptive smurfing behaviors that traditional AML systems may overlook.
  • Enhance Fraud Detection: Strengthen existing fraud detection frameworks to identify suspicious transaction patterns indicative of mule account activity, especially those involving rapid fund dispersion.
  • Educate Employees: Train employees on the latest tactics used by money mules and the sophisticated methods they employ to bypass security measures.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingransomwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Attackers Hide Linux Malware in SSH-Named Files During Package Installs

Next Post

InvisibleFerret Malware Evades Detection with New .pyd and .so File Types

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us