Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure) — Threadlinqs Intelligence
As of 2026-08-22, Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure) is a high-severity phishing threat attributed to Unknown (tracked by Group-IB as two operations: GoldBull, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 13 indicators of compromise.
Threat ID: TL-2026-2109 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Unknown (tracked by Group-IB as two operations: GoldBull · FINANCIAL
Group-IB documents two organized fraud operations, GoldBull and CoinLure, that use deepfake video ads impersonating financial professionals, economists, and regulators to funnel retail investors into
Group-IB's fraud-intelligence research, published August 20-21, 2026, describes two related but distinct investment-fraud operations. GoldBull runs deepfake social-media advertisements impersonating financial professionals and public figures (Group-IB documented over 20 fake WhatsApp/social accounts impersonating a single Australian economist) with deliberately short ad lifespans to manufacture urgency and evade moderation. Geo-targeted redirects funnel victims into private WhatsApp groups of roughly 1,000 members each, run by a fake 'head analyst' persona who names a small-cap, NASDAQ-listed stock, a buy price, and a profit target. Victims are required to purchase through legitimate brokerages and submit proof of execution, letting the operators pre-position and then exit their own holdings once coordinated buying moves the price -- a documented November 2025 case saw a stock rise 12.4% (from a $24.79 signal to a $27.87 peak) before the operators exited and the price collapsed 42% below entry by February 2026. Two to three concurrent WhatsApp groups can generate an estimated $1.5-3M in victim capital per campaign.
CoinLure industrializes the fake-investment-platform model: victims arrive via SEO-optimized content, paid social advertising, or romance-scam grooming, then pass through fake registration, counterfeit KYC checks (including fabricated ASIC registration numbers to appear licensed), and trial-fund traps into tiered 'investment plans.' Deposits are accepted only in cryptocurrency (BTC, ETH, USDT-TRC20). When victims attempt to withdraw, operators impose scripted friction: minimum-balance requirements, fabricated 10-30% 'tax' or 'insurance' fees, forced account upgrades, indefinite 'technical issues,' or a compliance freeze. The same operators subsequently resurface as a fund-recovery service demanding a further upfront fee. Group-IB linked one confirmed CoinLure platform (tethergloballtd.com, with on-chain deposits observed since 2022) to 208 other domains sharing 23 near-identical website templates, the same hosting infrastructure, and repeated registrant contact details (name, email, phone, address), evidencing centralized, common operator control across the cluster. Estimated combined network revenue across the 208-domain cluster is $187M; stolen cryptocurrency was traced moving directly to KYC-compliant centralized exchanges without obfuscation.
Both operations sit inside a broader wave of AI-deepfake investment-fraud activity documented by the Australian Securities and Investments Commission (ASIC) in the same week: ASIC reported removing 19,400 scams in the prior 12 months (a 182% year-over-year increase) and over 33,400 scam websites/social posts over three years, with Australians reporting more than $2B in total scam losses in 2025 ($837.7M of it investment-fraud specific -- the same figure cited in the originating hunt article). Separately reported deepfake impersonation targets in this same Australian wave include Prime Minister Anthony Albanese, ABC finance journalist Alan Kohler, economist Stephen Koukoulas (deepfaked promoting an 'undervalued stock' and directing viewers to a WhatsApp trading community -- structurally identical to the GoldBull mechanic), RBA Governor Michele Bullock, and several other public figures, with Scamwatch reports tied to these ten most-impersonated figures alone totaling $7.4M in FY26 losses. Meta (Facebook/Instagram) hosted the majority of the underlying scam advertisements per ASIC.
Target sectors: finance, retail-investors, cryptocurrency
Target regions: australia, united states of america
Timeline
- On-chain analysis of the confirmed CoinLure platform tethergloballtd.com shows BTC/ETH/USDT-TRC20 deposits dating back to 2022, indicating the fraud infrastructure predates public disclosure by several years.
- A GoldBull WhatsApp 'head analyst' persona instructs group members to buy a NASDAQ-listed small-cap stock at $24.79 with a $29.00 target.
- The signaled stock peaks at $27.87 (12.4% gain from entry); GoldBull operators exit their pre-positioned holdings without the promised $29 target being reached.
- By February 2026 the signaled stock has fallen to $14.27, 42% below the original entry price, after operators exited their positions.
- Australian media reports a hijacked-identity impersonation scam warning describing a deepfake of economist Stephen Koukoulas directing viewers to a WhatsApp trading community with an 'undervalued stock' tip, structurally matching the GoldBull mechanic.
- ASIC and ABC News report AI deepfake investment scams as 'an emergency in the making,' citing 19,400 scams removed in the prior 12 months (182% YoY increase) and $837.7M in 2025 Australian investment-scam losses.
- Bitdefender Labs publishes a tally of the ten most-impersonated Australian public figures in AI deepfake investment ads (including PM Anthony Albanese, Alan Kohler, and Stephen Koukoulas), tied to $7.4M in FY26 Scamwatch-reported losses.
- Group-IB publishes 'One Adversary: Fraud Is a Network, Not a Payment' and 'The Architecture of Deception,' naming the GoldBull and CoinLure operations and documenting CoinLure's 208-domain/23-template infrastructure cluster and estimated $187M network revenue.
- GBHackers publishes coverage summarizing the Group-IB GoldBull/CoinLure research, the originating source for this threat record.
Related threats
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTC
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic Withdrawal Blocking (CloudSEK 'Hit Wicket' Report)
- Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East Banking Customers (SOCRadar STRU)
- Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts (Outsider Enterprise / Google v. Does 1-25)
- Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 13 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1598, T1589, T1583.001, T1583.006, T1583.008, T1585.001, T1585.002, T1588.007, T1608.006, T1566.002