Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)
Deepfake Investment Scam Ads Funnel Victims Into (TL-2026-2109), also tracked as GoldBull, is a high-severity phishing campaign, first published 2026-08-21. It is attributed to CoinLure with low confidence, maps to 12 MITRE ATT&CK techniques (T1566.002, T1583.001, T1583.006), and is covered by 9 detection rules and 13 indicators of compromise.
Key facts for TL-2026-2109
- Threat ID
- TL-2026-2109
- Also known as
- GoldBull, CoinLure
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-08-21
- Last reviewed
- 2026-08-21
- Attribution
- CoinLure
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, retail-investors, cryptocurrency
- Target regions
- australia, united states of america
- Detection rules
- 9
- Indicators of compromise
- 13
Group-IB documents two organized fraud operations, GoldBull and CoinLure, that use deepfake video ads impersonating financial professionals, economists, and regulators to funnel retail investors into private WhatsApp 'analyst' groups running pump-and-dump stock signals or into fake KYC-gated investment platforms that later block withdrawals. CoinLure's confirmed infrastructure links 208 domains across 23 shared templates and common hosting, with an estimated $187M in network revenue.
How Deepfake Investment Scam Ads Funnel Victims Into works
Group-IB's fraud-intelligence research, published August 20-21, 2026, describes two related but distinct investment-fraud operations. GoldBull runs deepfake social-media advertisements impersonating financial professionals and public figures (Group-IB documented over 20 fake WhatsApp/social accounts impersonating a single Australian economist) with deliberately short ad lifespans to manufacture urgency and evade moderation. Geo-targeted redirects funnel victims into private WhatsApp groups of roughly 1,000 members each, run by a fake 'head analyst' persona who names a small-cap, NASDAQ-listed stock, a buy price, and a profit target. Victims are required to purchase through legitimate brokerages and submit proof of execution, letting the operators pre-position and then exit their own holdings once coordinated buying moves the price -- a documented November 2025 case saw a stock rise 12.4% (from a $24.79 signal to a $27.87 peak) before the operators exited and the price collapsed 42% below entry by February 2026. Two to three concurrent WhatsApp groups can generate an estimated $1.5-3M in victim capital per campaign.
CoinLure industrializes the fake-investment-platform model: victims arrive via SEO-optimized content, paid social advertising, or romance-scam grooming, then pass through fake registration, counterfeit KYC checks (including fabricated ASIC registration numbers to appear licensed), and trial-fund traps into tiered 'investment plans.' Deposits are accepted only in cryptocurrency (BTC, ETH, USDT-TRC20). When victims attempt to withdraw, operators impose scripted friction: minimum-balance requirements, fabricated 10-30% 'tax' or 'insurance' fees, forced account upgrades, indefinite 'technical issues,' or a compliance freeze. The same operators subsequently resurface as a fund-recovery service demanding a further upfront fee. Group-IB linked one confirmed CoinLure platform (tethergloballtd.com, with on-chain deposits observed since 2022) to 208 other domains sharing 23 near-identical website templates, the same hosting infrastructure, and repeated registrant contact details (name, email, phone, address), evidencing centralized, common operator control across the cluster. Estimated combined network revenue across the 208-domain cluster is $187M; stolen cryptocurrency was traced moving directly to KYC-compliant centralized exchanges without obfuscation.
Both operations sit inside a broader wave of AI-deepfake investment-fraud activity documented by the Australian Securities and Investments Commission (ASIC) in the same week: ASIC reported removing 19,400 scams in the prior 12 months (a 182% year-over-year increase) and over 33,400 scam websites/social posts over three years, with Australians reporting more than $2B in total scam losses in 2025 ($837.7M of it investment-fraud specific -- the same figure cited in the originating hunt article). Separately reported deepfake impersonation targets in this same Australian wave include Prime Minister Anthony Albanese, ABC finance journalist Alan Kohler, economist Stephen Koukoulas (deepfaked promoting an 'undervalued stock' and directing viewers to a WhatsApp trading community -- structurally identical to the GoldBull mechanic), RBA Governor Michele Bullock, and several other public figures, with Scamwatch reports tied to these ten most-impersonated figures alone totaling $7.4M in FY26 losses. Meta (Facebook/Instagram) hosted the majority of the underlying scam advertisements per ASIC.
MITRE ATT&CK techniques used in TL-2026-2109
Initial Access
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1583.008 Malvertising; T1585.001 Social Media Accounts; T1585.002 Email Accounts; T1588.007 Artificial Intelligence; T1608.006 SEO Poisoning
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Impact
Defense Evasion
Remediation for Deepfake Investment Scam Ads Funnel Victims Into
Immediate actions
- Advise retail customers to independently verify any investment tip or analyst credential before trading and to never act on a stock/crypto recommendation sourced solely from a WhatsApp/Telegram signal group
- Report and request takedown of deepfake ads and fraudulent platforms through platform trust & safety channels (Meta, YouTube, TikTok) and national regulators (ASIC Scamwatch, US FTC)
- Brokerages should flag and monitor for coordinated, synchronized buy orders concentrated in low-float small-cap tickers, consistent with pump-and-dump signal-group activity
- Block or monitor traffic to confirmed fraud infrastructure (e.g. tethergloballtd.com and domains sharing its hosting/template fingerprints) once identified by threat intel
Workarounds
- Consumers should treat any investment offer routed through a private WhatsApp/Telegram 'analyst' group as high-risk regardless of the presenter's apparent identity
- Verify regulator registration/license numbers (e.g. ASIC) directly on the regulator's official public register rather than trusting numbers displayed on the investment platform itself
Longer-term hardening
- Deploy brand-protection and deepfake-detection monitoring across social ad platforms for unauthorized synthetic use of executives', economists', journalists', and regulators' likenesses
- Financial institutions should implement transaction-pattern analytics to detect coordinated small-cap pump-and-dump activity correlated with social-media signal groups
- Regulators and ad platforms should expand proactive scam-site/ad takedown programs and cross-share domain/template/registrant fingerprints with industry threat-intel partners
- Crypto exchanges should apply enhanced KYC/AML scrutiny to deposits traced to wallets/addresses flagged via on-chain analysis of confirmed fraud platforms
Timeline of Deepfake Investment Scam Ads Funnel Victims Into
- On-chain analysis of the confirmed CoinLure platform tethergloballtd.com shows BTC/ETH/USDT-TRC20 deposits dating back to 2022, indicating the fraud infrastructure predates public disclosure by several years.
- A GoldBull WhatsApp 'head analyst' persona instructs group members to buy a NASDAQ-listed small-cap stock at $24.79 with a $29.00 target.
- The signaled stock peaks at $27.87 (12.4% gain from entry); GoldBull operators exit their pre-positioned holdings without the promised $29 target being reached.
- By February 2026 the signaled stock has fallen to $14.27, 42% below the original entry price, after operators exited their positions.
- Australian media reports a hijacked-identity impersonation scam warning describing a deepfake of economist Stephen Koukoulas directing viewers to a WhatsApp trading community with an 'undervalued stock' tip, structurally matching the GoldBull mechanic.
- ASIC and ABC News report AI deepfake investment scams as 'an emergency in the making,' citing 19,400 scams removed in the prior 12 months (182% YoY increase) and $837.7M in 2025 Australian investment-scam losses.
- Bitdefender Labs publishes a tally of the ten most-impersonated Australian public figures in AI deepfake investment ads (including PM Anthony Albanese, Alan Kohler, and Stephen Koukoulas), tied to $7.4M in FY26 Scamwatch-reported losses.
- Group-IB publishes 'One Adversary: Fraud Is a Network, Not a Payment' and 'The Architecture of Deception,' naming the GoldBull and CoinLure operations and documenting CoinLure's 208-domain/23-template infrastructure cluster and estimated $187M network revenue.
- GBHackers publishes coverage summarizing the Group-IB GoldBull/CoinLure research, the originating source for this threat record.
Sources cited for Deepfake Investment Scam Ads Funnel Victims Into
- Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts
- One Adversary: Fraud Is a Network, Not a Payment
- The Architecture of Deception: How a $187 Million Fraud Ecosystem Exploits Trust Across Australia and the United States
- Scammers Use WhatsApp Groups to Coordinate Millions in Victim Trades and Pump Real Stocks
- AI deepfake scams 'an emergency in the making' as ASIC reports rise in false investment endorsements
- Top Aussie public figures impersonated in investment scams
Threats related to Deepfake Investment Scam Ads Funnel Victims Into
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTC
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic Withdrawal Blocking (CloudSEK 'Hit Wicket' Report)
- Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East Banking Customers (SOCRadar STRU)
- Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts (Outsider Enterprise / Google v. Does 1-25)
- Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains
Detection coverage for TL-2026-2109
As of 2026-08-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2109 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.