Sophos has released details of two expansive, still operational fraud scams operating out of Asia. Both are pig butchering or sha zhu pan rings (elaborate and lengthy financial fraud scams that can cost victims thousands of dollars) that directly targeted the organisation’s principal threat researcher, Sean Gallagher.
The first, based in Hong Kong, involves a fake gold trading marketplace. The second is Cambodia-based and has ties to Chinese organised crime; Sophos says it has netted the scammers $500,000 in just one month.
Rather than the traditional approach of contact via a dating app, the scammers reached out to Gallagher via Twitter and text message.
Sophos is releasing details in a two-part series, with part one, Fool’s Gold: Dissecting a Fake Gold Market Pig Butchering Scam, available now. It focuses on the inner workings of the ring based out of Hong Kong, which demonstrates how these scammers are upping their technical sophistication to lure in and con targets.
“For two years, we’ve been following and reporting on a subset of these pig butchering schemes called CryptoRom,” Gallagher said.
“This is a particular flavour of pig butchering that relies on romance-based lures with scammers approaching potential victims on dating apps and then asking them to invest in fraudulent crypto trading apps. But CryptoRom is really just the tip of the iceberg. Since the start of the pandemic, this type of cyber fraud has massively expanded.
“These scammers are now targeting people on all major social media platforms or even direct message, and they’re not limiting themselves to just exploiting crypto but also gold and other forms of currency or trading value. They’re quite literally going after the whole hog,” he said.
In the first scam Gallagher investigated, he spent three months interacting with one of the scammers after they approached him directly on Twitter. The scammer posed as a 40-year-old woman from Hong Kong who quickly attempted to move the conversation to WhatsApp. From there, the scammer tried to convince Gallagher to invest in a fake gold trading marketplace, touting her connections with her “Uncle Martin” — supposedly a former Goldman Sachs analyst. She then directed him to a site that copied the branding of a legitimate Japanese banking company called Mebuki Financial, where the foreign exchange and commodity trading services were to be conducted.
While the social engineering of this scam was less polished than other cases Sophos has investigated, it showed a marked increase in technical sophistication for these types of groups. The scammers used an elaborate combination of highly effective SEO, polished scam pages to “register” new clients on their fake Mebuki website, and a pirated version of a legitimate trading app (MetaTrader 4) with additional malicious code to steal money from their victims. They are also actively updating their operation’s scam infrastructure to avoid being shut down.
“Both scam rings are still operational and will be difficult to shut down. While we marked the domains and IP addresses being used by the attackers in the Hong Kong ring as malicious, their scam operations have already shifted to new domains. They already have a new download infrastructure in place for their pirated version of the MetaTrader app, so, at this point, we’re essentially playing ‘whack-a-mole’,” Gallagher said.
“Unfortunately, that’s the reality as these operations become broader in scope, targeting more regions and across different platforms. The move from crypto to gold also shows how easily these groups can find a new niche to exploit. That means the best defence is public awareness of these types of scams. People should be wary of any SMS, dating app or social media direct message from a stranger who strikes up a conversation and then suggests moving it to WhatsApp or Telegram — especially if they make claims about wealth obtained from crypto or other trading,” he said.