A major pig-slaughtering operation (shā zhū pán) was observed using fake cryptocurrency trading pools to trick its victims into handing over their savings, and likely made over $1 million over the course of the scam, according to new information , which were published by the Sophos X-Ops research team.
This is the latest in a series of ongoing research disclosures from Sophos researchers studying so-called pig slaughter scams – the practice of conning victims out of their money through a combination of romantic social engineering lures and fraudulent crypto trading.
In early 2023, they detailed how these cybercriminal gangs, usually based in the Asia-Pacific region, got their malicious apps listed in the Apple and Google mobile app stores by circumventing security measures and turning into chatbots with generative artificial intelligence (AI) to defraud their victims.
The latest twist in the saga sees the pig butchers setting up fraudulent domains that take advantage of the essentially unregulated world of decentralized finance (DeFi) crypto trading apps.
As part of their functionality, such apps create liquidity pools of various cryptocurrencies that users can access to trade from one to another, with those who participate in the pool receiving a percentage of the fee paid when a trade is made. To join pools, participants generally must sign an online contract that gives pool operators permission to access their crypto wallets to trade. This is generally an extremely risky practice.
At first glance, the pig slaughter ring tracked by Sophos operates in much the same way as a legitimate ring, creating pools of cryptocurrency assets and adding new traders – or in this case, victims – until the cybercriminals have robbed the entire pool for themselves . This is called a rug pull. When combined with the traditional romance novel Pig Slaughter, it can be extremely effective, as Sean Gallager, senior threat researcher at Sophos, has observed.
“When we first discovered these fake liquidity pools, they were rather primitive and still in development. “Now we’re seeing shā zhū pán scammers take advantage of this particular form of cryptocurrency fraud and seamlessly integrate it into their existing tactics, such as luring targets via dating apps,” explained Gallagher.
“Very few understand how legitimate cryptocurrency trading works, so it is easy for these scammers to defraud their targets. There are now even toolkits for this type of fraud, making it easier for various pig slaughterhouses to add this type of crypto fraud to their arsenal. While Sophos tracked dozens of these fraudulent “liquidity pool” sites last year, we are now seeing more than 500.”
A little song about Frank and Vivian
Gallagher first became aware of this particular group of scammers when he was contacted by Frank, a victim who had read some of the earlier research. Frank – that is not the victim’s real name – thought he was connecting on the dating app MeetMe with a woman named Vivian who said she was a German citizen living in Washington DC.
Frank and Vivian chatted online for a few weeks. During this time, Vivian, who was of course the scammer, mixed romantic promises with persistent attempts to get Frank to invest in crypto assets, as is common with scammers.
Unfortunately for Frank, he was persuaded to open an account with the legitimate dollar-to-cryptocurrency conversion service Trust Wallet, which he connected to the liquidity pool Vivian recommended to him.
At several points during their conversation, Frank almost stumbled upon the ruse when the scammer – apparently by mistake – wrote messages to him in Chinese instead of English, but was able to convince him that she had mistakenly copied text from a translation app, with which she spoke to a friend in China, in her chat.
After a long process – Frank was initially skeptical about cryptocurrency investments – he was lured to the fake pool site that convincingly spoofed the brand of established DeFI platform provider Allnodes. He deposited $22,000 into the pool between May 31 and June 5, 2023, and just three days later discovered that his wallet had been emptied.
To get his money back, Frank contacted Vivian, who claimed he would have to deposit additional funds to do so. Frank got his bank to approve a money transfer to Coinbase, but while this was happening, he started doing research, after which he learned about Sophos’ work and got in touch.
During the ensuing conversation, Gallagher told Frank to block his contact, but Vivian tracked him down on Telegram and continued to try to trick him into leaving with even more money. At one point she sent a long and apparently emotional latter – probably an AI creation.
Gallagher said this new variant of the pig slaughter scam presents a particularly thorny problem because, unlike some other variants, no malware or fake app requires downloading to the victim’s device – in fact, the entire fake pool can run through legitimate services like Trust Wallet ; At one point, Frank tried to contact Trust Wallet’s technical support team, but the pig butchers connected him to a false contact instead.
And herein lies a large part of the problem, said Gallager, because there is no regulation of liquidity pools, even if they are supposedly legitimate.
“These scams are successful solely through social engineering, and the scammers are persistent,” he said. “The only way to protect yourself from these scams is to be vigilant and know that they exist and how they work. That’s why Frank wanted to share his story.
“Users need to be wary if they suddenly connect with someone they don’t have contact with on a dating app or social media platform, especially if the ‘person’ moves the conversation to a platform like WhatsApp and then talk about investing in cryptocurrencies.”
If you need help
A more detailed account of Frank’s experiences can be found on the Sophos blog, and Gallagher and his colleague Jagadeesh Chandraiah are still keen for other victims to come forward confidentially.
In the meantime, if you believe you have been working with a pork butcher and may be using a fake liquidity pool app, there are a number of things you can do:
- Use the Revoke website – https://revoke.cash/ – from your wallet app or browser to break the contract for the wallet to identify and revoke permissions (this is not a free service);
- Transfer your funds to a new wallet, especially if you cannot break the contract;
- Contact the exchange where you purchased the cryptocurrency through your wallet provider. Do not contact support chats on the liquidity pool app itself as these are likely controlled by the pig slaughterers. This is a link to the real Trust Wallet helpdesk.
- Collect the transaction data associated with your wallet using a blockchain explorer like Etherscan by pasting your wallet ID into the search. You can pass this information on to security teams and the police;
- If the robbery has taken place and your money has disappeared, under no circumstances should you contact any crypto recovery provider advertised on social media – generally these are also scams;
- Report the activity to the appropriate authorities. In England and Wales, Action Fraud should be your first port of call. In Scotland you should instead contact Police Scotland on 101 and readers in Northern Ireland can also contact Action Fraud. In the US, both the US Secret Service and the FBI have the authority to investigate crypto fraud, although they may not always act on individual cases.
- Understand that you are not alone. These scams are sophisticated and their perpetrators are experts at manipulation – there is no shame in falling victim to such a scam.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.