Friday, August 21, 2026

Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts

Investment fraud is increasingly exploiting the one action banks struggle most to block: a payment the customer actively wants to make.

Deepfake advertisements, impersonated financial experts, and coordinated WhatsApp groups are now being used to steer retail investors into manipulated stock trades and fake investment platforms.

In 2025, investment scams became the largest fraud-loss category in both Australia and the United States.

Australian victims reported losses of $837.7 million, while US investment-scam losses reached $7.9 billion, illustrating the scale of a threat driven by synthetic media, social engineering and industrialised fraud infrastructure.

GoldBull uses deepfake social-media advertisements that impersonate financial professionals to create credibility and urgency.

The ads are deliberately short-lived, helping operators evade moderation while directing selected users through geo-targeted redirects into WhatsApp groups.

Inside those groups, a fake “head analyst” provides what appears to be precise trading guidance: a named small-cap stock, a target purchase price and an expected exit level.

Victims are encouraged to buy shares through legitimate brokerages, which gives the activity an appearance of authenticity and ensures victims not the criminals execute the transactions.

The operational goal is a coordinated pump-and-dump. Group-IB documented a case in which members were instructed on November 6, 2025, to purchase a NASDAQ-listed stock at $24.79 with a target of $29.

The stock later peaked at $27.87, a 12.4% rise, before the operators allegedly sold pre-positioned holdings. By February, the stock had fallen to $14.27 42% below the victims’ entry price.

A handful of WhatsApp groups, each with roughly 1,000 participants, can create enough concentrated buying pressure to move thinly traded equities. Group-IB estimates victim capital of $1.5 million to $3 million per campaign.

Victims reach fraudulent investment sites through SEO-optimised content, paid social advertising, or romance-scam grooming, then encounter a polished onboarding flow featuring registration, counterfeit KYC checks, trial funds, and tiered investment plans.

Once deposits have been made, withdrawals are blocked through scripted friction.

Victims may be told they need to meet a minimum balance, pay 10% to 30% in supposed taxes or insurance, upgrade their account, or wait through an indefinite “technical issue” or compliance freeze.

In some cases, the same network later reappears as a recovery service and requests another upfront payment.

Group-IB’s research highlights two distinct operations GoldBull and CoinLure that demonstrate how scammers are combining deepfake advertising with trusted platforms, social channels and increasingly professional fraud workflows.

The critical defensive insight is that these fraud rings may be difficult to stop at the payment stage but remain exposed through their infrastructure.

Shared hosting, cloned templates, recurring contact details, reused wallets, beneficiary accounts, redirect chains and WhatsApp-number patterns create linkable indicators across campaigns.

Fraudsters rely on scale to profit, but scale also creates a graph for defenders to map.

Deepfake Investment Scam

Group-IB found that one confirmed CoinLure platform was connected to 208 domains using 23 shared templates, common hosting and repeated contact details; the network’s estimated revenue was $187 million.

Fusion’s end-state architecture: capabilities on one data model inside the institution, extended across institutions by a privacy-preserving network layer (Source : Group-IB).
Fusion’s end-state architecture: capabilities on one data model inside the institution, extended across institutions by a privacy-preserving network layer (Source : Group-IB).

That means detection teams should treat an impersonation ad or malicious domain as an entry point, not an isolated incident.

Correlating ad creatives, landing pages, domain-registration data, infrastructure fingerprints, payment destinations and analyst personas can expose a broader ecosystem.

Automated disruption can then reduce a campaign’s available victim-exposure time from hours to minutes.

Financial institutions also need earlier signals. Scam victims may exhibit changes in banking-app usage, including unusual sessions or altered transaction behaviour, before high-value transfers occur.

On their own, these anomalies can be noisy. Combined with external intelligence on an active scam network, they can become a practical pre-payment intervention trigger.

Cross-bank intelligence sharing is central to detecting mule accounts and beneficiary infrastructure that would otherwise appear benign at a single institution.

Group-IB’s Cyber Fraud Intelligence Platform uses distributed tokenisation to let participants correlate suspicious identifiers without sharing raw personally identifiable information.

The company says tokenisation occurs inside each participant’s environment, while shared tokens enable detection of connected risks across organisations.

The platform describes a typical fraud warm-up period of four to eight weeks, during which mule accounts may conduct low-value probe payments before large-scale fraud begins.

Detecting these behaviours across institutions can enable blocks, holds or customer interventions before an authorised payment is sent.

Deepfake investment scams will continue to exploit consumer trust, legitimate brokerages and the perceived authority of financial analysts.

But the same repeatable infrastructure that makes these operations scalable also gives defenders the evidence needed to identify, disrupt and trace the networks behind them.

★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft

A Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable...

Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access

Cybersecurity researchers have revealed a critical vulnerability in N-able’s...

OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing

OpenAI has reaffirmed its commitment to Zero Data Retention...

Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords

A business email compromise campaign is using emoji-filled JScript...

Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing

Quarkslab has argued that LLM-assisted reverse engineering does not...

Related Articles

Recent News