ThreatBeaconXThreatBeaconXSubscribe
HighPhishing · 9 min read · 45 views

Scammers Use WhatsApp Groups and Deepfakes to Manipulate Stock Markets

Scammers are using deepfake advertisements, targeted redirects and WhatsApp groups to lure investors into coordinated stock-pumping schemes. Victims are encouraged to buy genuine small-cap stocks through legitimate brokerages, creating real buying pressure that allows fraudsters to sell their pre-positioned holdings at a profit. A related operation, CoinLure, uses fake investment platforms and recovery-fee scams to extract additional money from victims.

Written by Team TBX·Published Aug 22, 2026

Cybercriminals are increasingly using WhatsApp groups, deepfake advertisements and social engineering to conduct investment fraud without directly compromising victims' bank or brokerage accounts.

Researchers at Group-IB identified two organized investment-fraud operations, GoldBull and CoinLure, that use different approaches to manipulate victims into transferring or investing their own money.

The campaigns demonstrate how legitimate platforms such as WhatsApp, social networks, banks and stock brokerages can be abused as part of a larger fraud ecosystem.

Key Highlights

  • Campaigns: GoldBull and CoinLure
  • Researcher: Group-IB
  • Primary platform: WhatsApp
  • Techniques: Deepfakes, social engineering and investment fraud
  • GoldBull uses WhatsApp groups to coordinate stock purchases.
  • Victims are directed to legitimate brokerages.
  • Fraudsters pre-position themselves in targeted stocks before directing victims to buy.
  • Two or three groups with approximately 1,000 members can reportedly generate $1.5–$3 million in buying activity.
  • CoinLure operates fake investment platforms.
  • CoinLure infrastructure was linked to 208 domains using 23 shared templates.
  • Estimated CoinLure network revenue: approximately $187 million

GoldBull WhatsApp Investment Scam

The GoldBull operation begins with advertisements impersonating financial professionals.

The advertisements reportedly use deepfake content to make fraudulent investment opportunities appear credible.

Potential victims are then filtered by location and redirected into WhatsApp groups.

Inside these groups, a convincing "head analyst" persona presents a supposedly exclusive investment opportunity.

Victims are provided with:

  • A specific small-cap stock
  • A recommended purchase price
  • A target price
  • Instructions to purchase the stock
  • Requests to provide proof of purchase

The objective is to create genuine buying pressure in a thinly traded stock. 

How the Stock Manipulation Works

The attack follows a simple but effective model:

Deepfake Advertisement
        ↓
Targeted Redirect
        ↓
WhatsApp Investment Group
        ↓
Fake Analyst / Investment Advice
        ↓
Victims Buy Genuine Stock
        ↓
Market Price Increases
        ↓
Scammers Sell Pre-Positioned Holdings
        ↓
Victims Are Left With Losses

The important distinction is that the victims may be using a completely legitimate brokerage account.

The fraud does not require the attackers to steal brokerage credentials.

Instead, the victims are manipulated into performing the transaction themselves.

Coordinated Buying Pressure

According to Group-IB, two or three WhatsApp groups containing approximately 1,000 participants can generate enough demand to influence a thinly traded stock.

The estimated amount of victim money involved in a campaign can reach approximately:

$1.5 million–$3 million

This demonstrates how social engineering can be combined with market manipulation to create financial impact without compromising financial infrastructure. 

Example of Stock Manipulation

In one documented case, victims were instructed on November 6, 2025 to purchase a NASDAQ-listed stock at approximately $24.79, with a target price of $29.

The stock later reached approximately $27.87 on December 9, representing a 12.4% increase.

The operators reportedly sold their previously acquired holdings at that point.

The promised target was never reached.

By February, the stock had fallen to approximately $14.27, leaving victims with substantial losses.

Fake Investment Platforms

The related CoinLure operation follows a different model.

Instead of manipulating genuine stocks, victims are directed to fraudulent investment platforms.

The operation reportedly uses:

  • Search-optimized websites
  • Social-media advertisements
  • Romance-scam grooming
  • Fake registration pages
  • Fake identity verification
  • Fake account balances
  • Trial investment funds
  • Tiered investment plans

The objective is to make the fraudulent platform appear legitimate before requesting increasingly larger deposits. 

Withdrawal Scam

Once victims attempt to withdraw their money, the fraudsters introduce additional requirements.

Victims may be told that they need to pay:

  • Taxes
  • Insurance fees
  • Minimum-balance requirements
  • Upgrade charges
  • Technical fees
  • Compliance-related charges

Reported fees can range from 10% to 30% of the requested withdrawal.

Even after paying, victims may still be unable to access their funds.

Recovery Scam

Some victims are targeted again after realizing they have been defrauded.

The attackers offer to recover the lost funds but demand an additional upfront payment.

This creates a second-stage fraud:

Initial Investment Scam
        ↓
Victim Attempts Withdrawal
        ↓
Withdrawal Fee Demand
        ↓
Victim Loses More Money
        ↓
"Recovery" Offer
        ↓
Additional Upfront Fee

Victims can therefore lose money multiple times through the same criminal ecosystem.

208 Fraudulent Domains

Group-IB linked one confirmed CoinLure investment platform to 208 domains.

The domains reportedly shared:

  • 23 website templates
  • Common hosting infrastructure
  • Repeated contact information

This infrastructure reuse provides an opportunity for defenders to identify related fraudulent websites after discovering a single known domain. 

Estimated Revenue

The infrastructure associated with the CoinLure operation was estimated to have generated approximately:

$187 million

This illustrates the scale that organized investment-fraud networks can achieve by combining automated infrastructure with social engineering. 

Abuse of Trusted Platforms

The campaigns demonstrate an important security trend.

Attackers do not necessarily need to compromise:

  • WhatsApp
  • Stock exchanges
  • Banks
  • Brokerage platforms

Instead, they abuse legitimate platforms to establish trust.

The attack therefore becomes:

Trusted Platform + Fake Identity + Social Engineering = Financial Fraud

Detection and Hunting Opportunities

Organizations should monitor for:

  • Suspicious investment advertisements.
  • Deepfake financial personalities.
  • Newly registered investment domains.
  • Multiple domains sharing identical website templates.
  • Reused phone numbers or contact information.
  • WhatsApp groups promoting guaranteed returns.
  • Requests for screenshots or proof of stock purchases.
  • Investment advice combined with urgent deadlines.
  • Suspicious redirects from social-media advertisements.
  • Fraudulent investment websites.
  • Unusual payment beneficiaries.
  • Repeated transfers to investment-related accounts.
  • Multiple customers sending funds to the same beneficiary.
  • Follow-up payments described as taxes, insurance or withdrawal fees.

Recommended Detection Logic

A potentially useful fraud-detection correlation is:

Investment Advertisement
        +
New / Low-Reputation Domain
        +
WhatsApp Contact
        +
Investment Payment
        +
Unusual Beneficiary

A stronger signal may occur when multiple customers are directed toward the same domain, phone number, beneficiary or cryptocurrency wallet.

Recommended Mitigations

  1. Verify investment advisers independently.
  2. Do not rely solely on social-media advertisements.
  3. Treat guaranteed or unusually high returns as warning signs.
  4. Verify stock recommendations through independent sources.
  5. Never provide screenshots of brokerage transactions to unknown groups.
  6. Avoid investment groups that pressure members to act immediately.
  7. Verify investment platforms through regulatory sources.
  8. Monitor newly registered investment domains.
  9. Use domain and infrastructure intelligence to identify related fraud sites.
  10. Banks should monitor unusual beneficiary patterns.
  11. Investigate multiple customers sending funds to common beneficiaries.
  12. Provide rapid fraud-reporting mechanisms.
  13. Educate users about deepfake investment advertisements.
  14. Warn customers about withdrawal-fee and recovery scams.

Threat Assessment

This campaign represents a High-severity financial fraud threat because it combines sophisticated social engineering with legitimate financial infrastructure.

The attackers do not necessarily need to steal credentials or compromise trading platforms. Instead, they manipulate victims into authorizing legitimate transactions themselves.

The use of deepfakes and WhatsApp communities further increases the credibility and scalability of the operation. 

Conclusion

The GoldBull and CoinLure campaigns demonstrate how modern investment scams increasingly operate as organized, technology-enabled fraud networks.

Security teams, financial institutions and individuals should focus not only on account compromise but also on behavioral indicators, fraudulent infrastructure, social-engineering patterns and coordinated beneficiary activity.

The combination of deepfake advertisements, WhatsApp groups, fake investment platforms and recovery scams allows attackers to exploit trust at multiple stages of the victim journey.

MITRE ATT&CK Mapping

T1566.002 — Phishing: Spearphishing LinkT1189 — Drive-by CompromiseT1583.001 — Acquire Infrastructure: DomainsT1036 — Masquerading