Showing posts with label china. Show all posts
Showing posts with label china. Show all posts

Monday, November 10, 2025

Crypto-less Crypto Investment Scams: A California Case

My readers will know by now that I am addicted to PACER - the Public Access to Court Electronic Records.  When I see headlines like this one, I am compelled to dive in and read every publicly released document related to the case.  

USAO Central California

The headline last month was that Shengsheng He, a 39 year old Chinese native living in La Puente California (described as being a resident of Los Angeles and Mexico City) had been sentenced to 51 months in prison and ordered to pay restitution in the amount of $26,867,242. The press release quotes Matthew Geleotti from the Attorney General's office:

 "The defendant was part of a group of co-conspirators that preyed on American investors by promising them high returns on supposed digital asset investments when, in fact, they stole nearly $37 million from U.S. victims using Cambodian scam centers.  Foreign scam centers, purporting to offer investments in digital assets have, unfortunately, proliferated."

When talking about Crypto Investment Scams, they certainly have "proliferated." They are currently the number one form of cybercrime financial losses in America, for the third year in a row, according to the FBI's IC3.gov.  When we refer to these "Pig Butchering" scams as Crypto Investment Scams, it is easy to forget that many "crypto" scams still rely on the tried and true method of wire transfers to shell companies. When we first started exploring Romance Scams and their link to Business Email Compromise, the mostly Nigerian scammers referred to these as "Wire-wire jobs." A wire goes from the victim to a shell company, and a second wire goes from the shell company to the ultimate beneficiary of the crime. While West African Organized Crime continues unabated, Chinese Organized Crime has taken the top spot and is learning that many of the methods of their West African predecessors are still quite useful.
(figures from the ic3.gov 2024 report)

In the Shengsheng He case each of the victims believed that they were wiring money to fund their crypto investments.  Despite believing they have purchased crypto currency with these funds, they cannot be traced on the blockchain because they do not exist on the blockchain!  The first wire transfer went to any of the dozens of shell companies that had been set up across America under the direction of Lu Zhang, an illegal immigrant from China. (Zhang pled guilty to "conspiracy to commit money laundering on 12NOV2024.)  The second wire in the "wire-wire" job would then send those funds to one of two bank accounts at Deltec Bank in the Bahamas in the name "Axis Digital Limited." Deltec Bank's website is titled "Deltec Bank: Ultra-Sophisticated Private Banking" and boasts of their "robust anti-money laundering framework." 


 


Axis Digital Limited served as an off-shore crypto exchange that seems to have been created for the purpose of taking "wire-wire" proceeds from Crypto Investment Scams and converting the funds to USDT before transferring them on to the Chinese Organized Crime gangs operating the scam centers in Sihanoukville, Cambodia.

The case is being prosecuted in the Central District of California in four parts.

Zhang, Wong, Walker, Zhu - Sea Dragon Trading & the Shell Companies

One of the cases focuses primarily on the network of US-based shell companies created to receive the wire transfers from the victims.  The victims believed they were funding their crypto investments, and would see "deposits" into their imaginary crypto investment accounts that corresponded to the amount of their wire transfers.  Court records show that "at least 284 transactions resulted in more than $80 Million in victim losses." The defendants in this case, with their ages as of December 14, 2023, were named in an initial press release entitled: "Four Individuals Charged with Laundering Millions from Cryptocurrency Investment Scmas Known as 'Pig Butchering'" 
  • Lu Zhang - (36, of Alhambra) was sentenced to 24 months + $7,560,014 restitution
  • Joseph Wong - (32, of Rosemead) was sentenced to 51 months + $7,560,014 restitution
  • Justin Walker - (31, of Cypress) was sentenced to 30 months 
  • Hailong Zhu - (40, of Naperville, Illinois) has not been sentenced yet
Sea Dragon Trading, LLC and Sea Dragon Remodel, Inc were two of the companies created by Hailong Zhu, but the list of shell companies below collectively sent $20,083,987 in wires to Deltec Bank in the Bahamas:
• BFC REMODEL, LLC;  - 408 W Glendon Way, San Gabriel, CA 91776
• BFC SUPPLY, LLC; - 408 W Glendon Way, San Gabriel, CA 91776 
• CREATIVE HOMEGOODS, LLC;  - 823 W Huntington Dr. Apt B, Arcadia, CA 91007
• FUYU COMMERCE, LLC;  - 1140 S El Molino St, Alhambra, CA 91801
• GOOD LUCK TRADING, LLC;  - 2220 Falling Leaf Ave, Rosemead, CA 91770
• HONG'S TRADING, LLC; - 1140 S El Molino St, Alhambra, CA 91801 
• KAIS TEA SET SUPPLIES, LLC;  - 508 Bellows Ct, Diamond Bar, CA 91765
• LEADING CONSTRUCTION, LLC;  - (multiple - unsure)
• LJS REMODELING, LLC;  - 1441 Paso Real Ave SPC 254, Rowland Heights, CA 91748
• LJS SUPPLY, LLC;  - 650 W Duarte Rd Suite 100B, Arcadia, CA 91007 
• LQH SUPPLY, LLC;  - 823 W Huntington Dr, Apt B, Arcadia, CA 91007
• MINGXING REMODEL, LLC;  - 4661 District Blvd, Vernon, CA 90058
• MINGXING TRADING, LLC;  - 2220 Falling Leaf Ave, Rosemead, CA 91770 
• QAG TRADING, INC. - 8811 Garvey Ave, 202, Rosemead, CA 91770 
• QAG TRADING, LLC;  - 3254 Evelyn Ave, Rosemead, CA 91770 
• SEA DRAGON REMODEL, INC;  - 4661 District Blvd, Vernon, CA 90058
• SEA DRAGON TRADING, LLC;  - 1140 S El Molino St, Alhambra, CA 91801
• SHANGHAI FOOD & GROCERIES, LLC;   - 250 W Valley Blvd, Ste M, San Gabriel, CA 91776
• SUNRISE SUPPLY, LLC;    - 823 W Huntington Dr. Apt B, Arcadia, CA 91007
• XIEYUNZHU TRADING, INC;  - 1441 71st STreet, Apt 1, Brooklyn, NY 11228 
• YHM SUPPLY, LLC;  - 401 S Canyon Blvd Unit C, Monrovia, CA 91016
• YHM TRADING, LLC;  - 401 S Canyon Blvd Unit C, Monrovia, CA 91016
• YZX LUXURY, LLC;  - 1036 S Garfield Ave, B, Alhambra, CA 91801 
• YZX TRENDING, LLC;    - 1036 S Garfield Ave, B, Alhambra, CA 91801 

Li & Zhang - the Telegram Connection

In a second case, the defendants were: 
  • Daren Li, 41
  • Yicheng Zhang (39, of China) (sentenced to 18 months and $1,047,226 in restitution)
Zhang & Li controlled four additional shell companies: 
• B&C Commerce, LLC - 180 E Valley Blvd Ste 202, San Gabriel, CA 91776 
• Jimei Trading - 785 King St, San Gabriel, CA 91776 
• SMX Beauty, Inc. - 132 E Emerson Ave, Unit C, Monterey Park, CA 91755 
• SMX Travel, Inc. - 132 E Emerson Ave, Unit C, Monterey Park, CA 91755 

The DOJ described Daren Li as "41, a dual citizen of China and St. Kitts and Nevis, and a resident of China, Cambodia, and the UAE." He was arrested 12APR2024 at the airport in Atlanta.  The DOJ press release "Two Foreign Nationals Arrested for Laundering at Least $73M through Shell Companies Tied to Cryptocurrency Investment Scams" says that Li and Zhang (a resident of Temple City, California) "instructed co-conspirators in the laundering network to open bank accounts in the names of various shell companies. Once the victims sent funds to the shell companies, Li and Zhang monitored the lower-level co-conspirators who transferred the proceeds overseas to bank accounts at Deltec Bank in The Bahamas." The funds were then converted to cryptocurrency and sent to wallets, including at least one controlled by Li. 

Zhang's communications revealed "extensive coordination to facilitate the international money laundering, including chats discussing the commission structure for the network, various shell companies used, victim information, and at least one video from a co-conspirator calling a U.S. financial institution." 

Daren Li is described as being "the leader of the syndicate."  Daren used his Telegram id (@KG71777) to communicate with the Cambodia-based members of the conspiracy.  (Daren's email was: darren1575687@gmail.com).  In court documents, the primary USDT address of the conspiracy is referred to as "the TRteo" address (for the first five characters of the address.)  While TRteo is not an uncommon prefix, there are certainly very few such addresses that have received in excess of $39 Million in deposits, much less the higher number mentioned in the press release of $341 Million! In fact, there is only one. 

Chinese Blockchain intelligence company "BlockSec" blogged about that wallet on their QQ page.  Using their tool, MetaSleuth, they were able to successfully identify the full wallet address, TRteottJGH5caJyy9qFuM8EJJGGCpDaxx6.  The wallet became inactive on 29APR2024, but from its initial transaction on 16APR2021, more than $300 Million USD in more than 16,000 deposits  flowed through that address, including transactions to and from HuionePay. 

BlockSec QQ Post

Because Daren Li is described as being in control of this USDT wallet, it is generally considered that he was the leader of this entire enterprise. In July 2022, a meeting was held in Phnom Penh of the top leadership. Daren Li, JingLiang Su, Shengsheng He, and Jose Somarriba were all present.  Daren Li also controlled a Binance account that received at least $4.5 Million in USDT that originated from "Bahamas Account #2." He was also the source of funds to create that "Bahamas Account #2 at Deltec Bank by transferring $999,383 in USDT. 

Jose Somarriba, Axis Digital, and Itemized Victim Losses 

Jose Somarriba (55, of Los Angeles) (sentenced to 36 months and $26,867,242.44 in restitution) is being held responsible for the losses from 174 victims.  Those victims are listed by their initials and the dollar amounts that each had stolen from them.  The average victim lost $154,409.44!  (The median loss was $61,250.) The victims who had the most money stolen were in the amounts: $5,616,000; $2,340,000; and $1,030,279! Nine victims experienced a theft of $500,000 or more. 

(extract from loss amounts for 174 victims) 

Somarriba was a co-founder of Axis Digital, along with Shengsheng He and Jingliang Su.  He was the one who opened the "Bahamas Account #1" at Deltec Bank which received $36.9 million in wire transfers from American bank accounts. He prepared fraudulent KYC forms to present to the banks as well as being primarily responsible for converting Deltec funds to USDT and transferring the funds to Cambodia via a USDT wallet referred to as "TRteo" in the court documents. 

Jingliang Su - the Dubai Connection

The final of the linked cases is the case of Jingliang Su, (44, of China and Turkey). Su was sentenced to 51 months in federal prison and to pay $26,867,242.44 in restitution.  

Preferring the name "James," Su resided in Dubai.  He was a director of Axis Digital and was a signatory to "Bahamas Account #1" at Deltec Bank. He is described as being "a citizen of China and St. Kitts and Nevis" and a resident of Cambodia, the UAE, and the People's Republic of China.

Friday, October 03, 2025

Scam Compound Operators: Members of The Four Great Families sentenced to death in China

(photo from BBC article "China sentences 11 members of mafia family to death")

On Monday this week, Chinese authorities sentenced to death 16 members of "The Four Families" for the multitude of crimes they committed while operating scam compounds in Northern Myanmar near the Chinese border. This was the culmination of an investigation that has been on-going since July 2023 and that we have been tracking primarily through Chinese Telegram channels that discuss the scam compounds.  Thirty-nine criminals were sentenced in the hearing. Eleven will be immediately executed, while five others have a two year reprieve, during which their sentences might be commuted to life in prison. Eleven more received life sentences, while the rest received sentences of between five and twenty-four years.  But who are The Four Families?  Read on . . .

The Incident at Crouching Tiger Villa - October 20, 2023

In Myanmar this is referred to as the "1020 Incident."  Crouching Tiger Villa, which is also called "Wohu Mountain Villa" was a telecom scam compound that covered 200 acres, and encompassed hotels, shopping malls, and buildings full of high tech equipment.  Ming Xuechang, who was the richest man in the Kokang Autonomous Region had a private army of 2,000 men to help patrol and protect the area. On October 20th a large group of prisoners, forced to work as cyber scammers, rioted and attempted to escape.  In the ensuing chaos, Ming's troops began to fire into the crowd, killing at least 60 (some say 70.) Rumors indicate that some of those killed were undercover Chinese police officers, but some say this is based on the plot of a Chinese movie with a similar theme.  

As a result, on November 12, 2023, the Criminal Investigation Bureau of the Ministry of Public Security issued a reward notice, offering a cash incentive for four leaders of the Myanmar Kokang group headed by Ming.  Within just a few days, all four had been arrested! 

Ming Guoping, Ming Julan, and Ming Zhenzhen were turned over to the Chinese police


Myanmar hands over 10 crime bosses to the Chinese - January 30, 2024

The Record: Crime bosses behind Myanmar cyber 'fraud dens' handed over to Chinese government

(image from: X.com/johnwSEAP )

On December 10, 2023, China issued arrest warrants for Bai Suocheng and ten other key leaders of the Kokang Autonomous Region's telecom and internet fraud rings.  Working with Myanmar's Ministry of Foreign Affairs, six of the ten were arrested and on January 30, 2024, sent to China to answer for their crimes. 

These are the ten in the China Warrant according to the Irawaddy


Two leaders of the Bai Family were among those sent back to China. The Bai family operated many casinos around Laukkaing, especially "the Silver Palace." They had many construction and logistics firm that served their own needs and those of the other families. Bai's most famous brand was the "Yum! Brands" which operated several other casinos that served as scam compounds as well. 

Bai Suocheng -白所成
Bai Yingcang - 白应苍

The Wei family was led by Wei Chaoren ( 魏朝仁 ), operating chiefly from Kongyang Township.  They were significant players in telecom infrastructure and provided SIM Pools for the use of the families.  The Henry Group was the chief company of Wei Chaoren, as well as The Xiaozhu.

Arrested: 
Wei Huairen - 魏怀仁 

Remaining at large from the Wei family were: 
Wei Rong
Wei Qingsong 

The Liu family also operated from Kongyang and other nearby border towns. The Liu family came to wealth in the mining industry and control most of the mining in Kokang.  They were significant players in money laundering. Liu's primary casinos were operated under the name "Fully Light Group." Liu Guoxi has also been linked to organ trafficking. Liu Zhengxiang was the founder of the Fulilai Group back in 1992 which operates a number of casinos in the area. His predecessor, Liu Abao, was known to be a significant drug trafficker.

Arrested: 
Liu Zhengxiang - 刘正祥
Liu Zhengmao - 刘正茂

Remaining at large from the Liu family was: 
Liu Zhengmao 

Ministry of Public Security - May 27, 2024

Ministry of Public Security spokesman Li Guozhong gave a major update on the strategy "Four Specializations and Two Joint Efforts" and their results.  He said that over the past five years, they had worked 1.945 million telecom network fraud cases and that for eight months in a row, they had significant declines in fraud as a result of their efforts.  The operation, which began in July 2023, had specifically targeted the "Four Major Families" ( “四大家族” ) in Kokang and had brought to justice members of the Bai, Wei, Liu, and Ming families. 

In this press conference, Li mentions that Ming Zhenzhen ( 明珍珍  ) had also been taken into custody. 

Myanmar's Cooperation with China's Ministry of Public Security 



September 28, 2024 - The Ministry of Public Security announced that they had made key arrests in Yangon and Mandalay, and that 20 "telecom network fraud crime group leaders and key members" had been arrested and were being handed over the China.  These included Chen Mouwei ( 陈某卫 ) and Yang Mou ( 杨某 ). The press release at that time said that Chen and Yang had "relied on the Four Great Families" of Myanmar's Kokang region, as well as criminal groups "such as Xu Laofa ( 徐老发 )" in order to "control armed forces, set up telecom fraud dens, and carry out telecom network fraud crimes targeting Chinese citizens.  They were also said to be suspected of intentional homicide, intentional injury and other serious violent crimes. 

The Crouching Tiger Villa arrests - December 30, 2024

"Tracking down and investigating the truth! The story of the investigation into the Mingjia criminal group in northern Myanmar.  Chinese people are being "traded" in northern Myanmar.

On December 30, 2024, China's Supreme People's Procuratorate published the first round of charges under the headline "Exposing the Northern Myanmar Mingjia Criminal Group's Fraud, Murder, and Drug-related Activities" ( 揭露缅北明家犯罪集团诈骗杀人涉毒解密数宗罪 ).  At that time, the Wenzhou Municipal court in Zhejiang Province charged 39 defendants, calling the Mingjia criminal group "one of the four major families in northern Myanmar.

They interviewed many victims, who told stories of the promises made to them by the "snakeheads" (a Chinese term for a human trafficker) and the reality they faced when they arrived.  One victim, Li Mouqian, from Guangdong, was sold to the Ming family and told he could buy his freedom for 300,000 Yuan. At Crouching Tiger Villa, he was expected to make 100 phone calls per day and to land three new victims of cyber scams each day.  If he failed to do so, he was beaten.  When he tried to escape with a colleague, he was beaten with steal pipes and his accomplice in the escape was beaten to death. 

The Ming family at that time was led by Ming Zhenzhen (明珍珍 ), the granddaughter of their founder Ming Xuechang (明学昌). Xuechang had been a part of Myanmar's Shan State legislature, representing the Kokang Self-Administered Zone as a member of the Union Solidarity and Development Party.  He was also in charge of the local police.  He controlled a personal army of at least 2,000 men. During a previous cross-border police action against Ming Xuechang, he shot himself rather than being captured, and died in the hospital leaving his granddaughter in charge. 

Between July 2023 and December 2024, the Chinese Ministry of Public Security managed to repatriate 53,000 telecom and internet fraud suspects from northern Myanmar. 


Tuesday, September 30, 2025

New Smish: New York Department of Revenue

 As I was visiting SmishTank to report the most recent SMish that I had received (an iMessage from a +27 South African telephone number claiming to be from ParkMobile) I noticed there had been many recent submissions from the New York Department of Revenue. SmishTank is operated by Professor Muhammad Lutfor Rahman, a colleague of mine from our time at UAB, and his student Daniel Timko from California State University San Marcos. 

SmishTank.com is a great resource for recent SMish!


Pennsylvania and Connecticut "Department of Revenue" also observed
The Utah State Tax Commission and the State of California Franchise Tax Board also seen

SMish that Hide from Wrong Browsers

If you visit any of the URLs that are reported by these "Tax Refund" phish, you'll find that they fail to resolve unless you are visiting from a phone. Researchers easily bypass this by using a "User Agent Switcher" which allows a browser, such as Chrome, to claim to be another device with a different browser.  By setting myself to be an "Android KitKat" version of Chrome, the pages render on my Windows PC just fine.  The User Agent Switcher also allows you to enter your own customer User Agents.  Today, this is the one I used ... 

Mozilla/5.0 (Linux; Android 4.4.2; Nexus 4 Build/KOT49H) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.114 Mobile Safari/537.36

New York Department of Revenue Mobile Phish (SMish)

After switching my browser agent, I chose to visit "revenue.refundjpt[.]cc/notice" to get samples of the phish. The first thing that stands out is that despite the SMish all claiming to be the "New York Department of Revenue" the phishing website calls itself "Department of Taxation and Finance" and makes no reference to any specific state. 



The "Address" page of the phish starts by asking for a Social Security Number, which makes sense if you are interacting about taxation.  With most "bank" phish, that would be an immediate Red Flag, but people who are interacting about taxes would not be alarmed by this.  In the USA, your SSN is the primary identifier for taxes.  Although the "State" is pre-populated to "New York" the footer still references the California Penal Code. 



The next page tells me they would like to refund me $1120 and asks which Credit Card or Debit Card I would like to send the funds to.  The "Bank Routing" option is unavailable, apparently due to "system maintenance." 



The website is using the Luhn algorithm to confirm that the credit card number is valid.  Type any 16 digits starting with a 4 or a 5, then rotate the final number until it stops saying "invalid card number" in red and accepts the number.  My made up number was 4381 6621 8355 371_ and when I changed the last digit to a "6" it became an acceptable Credit Card number.  (I looked it up later, as this was entirely fictitious, but 438166 would mean my card was a Visa Credit Classic issued by Multicredit, S.A., in Guatemala.  Oops!  Its ok, the Chinese scammers didn't care.) 

After this, the criminals sent a text message to the burner phone that I had provided in the Address block. This is a CRITICAL PART OF THEIR STRATEGY!

The "SERCURTITY" verification (yes, securTity) asks for my 6-digit code.  While they say this is because they want my tax refund to be secure, this code is actually the 2-Factor Authentication that allows them to add MY CREDIT CARD to THEIR PHONE's WALLET!




Unfortunately, Guatemala Multicredit SA must have let them know that my credit card didn't really exist, as it booted me back to the credit card page and asked for a different card. This actually happens even if you enter a VALID card.  Why?  The criminals are not interested in sending you a tax refund. They are interested in loading your debit and credit cards onto their phone in Bangkok (or wherever their "machine room" full of spam-sending phones is located.) If you will give them two cards, they will load two.  If you will give them three cards, they will steal all three.  

How does the Stolen Credit Card get used? 

They then deploy "Shoppers" to begin making purchases using your credit card which is now "Tap to Pay" ready on their phone!  The phone is in Bangkok?  No problem.  They use the software "X-NFC" to "remote tap" transmitting the card loaded on the wallet in Asia to the phone standing at the payment til at the Apple Store in Burbank.


I'm attaching a promotional video that the author shares on his Telegram channel.  In the video, the criminal has two phones "above" his Point of Sale device.  He links the NFC capability of one of the top phones to the bottom phone.  He then taps the top "linked phone" to an iPhone holding a credit card in his wallet.  The image of the card is transferred to the bottom phone, which he can then successfully tap on the Point of Sale device.  


In practice, the "bottom phone" would be somewhere in North America.  The person using that phone would call a collaborator in Asia to say they are ready to make a purchase.  The remote agent then taps one of the phones where your Phished credit card is loaded.  That card is now "usable" on the phone in North America, who taps the phone locally to make a payment using the credit card 7500 miles away! 

What Registrars, Hosts, and Domains are part of the current New York campaign?

These iMessage and RCS phish are part of a deployment server where criminals pay a monthly fee to use the phishing sites.  Each criminal can choose how and where they register their domains and how and where they host the phishing websites.  Because they are all renting access to the same catalog of phishing website, the sites may look identical while having very different hosting and registration models.

In this case, the main set of domains is registered at "Dominet (HK) Limited" while the hosting is more difficult since they are hiding behind Cloudflare's Reverse Proxy service.  The bulk of that group's domains for this campaign were registered on September 27, 2025. 

The New York campaign used the hostname "revenue" with URLs using this pattern: 

hxxps://revenue.refundyt[.]cc/notice
hxxps://revenue.refundql[.]cc/notice
hxxps://revenue.refundmj[.]cc/notice
hxxps://revenue.refundrm[.]cc/notice
hxxps://revenue.refundet[.]cc/notice
hxxps://revenue.refundjc[.]cc/notice
hxxps://revenue.refundyt[.]cc/notice
hxxps://revenue.refundxu[.]cc/notice
hxxps://revenue.refundxe[.]cc/notice
hxxps://revenue.refundvs[.]cc/notice
hxxps://revenue.refunduw[.]cc/notice
hxxps://revenue.refundte[.]cc/notice
hxxps://revenue.refundsz[.]cc/notice
hxxps://revenue.refundrm[.]cc/notice

Another group of domains, which was first seen on September 26th and includes 28 domains, some of which were registered today, was also registered at Dominet (HK) Limited and also hiding behind Cloudflare uses the pattern: 

hxxps://revenue.paybds[.]cc/notice
hxxps://revenue.paydjr[.]cc/notice
hxxps://revenue.paydqo[.]cc/notice
hxxps://revenue.payeoc[.]cc/notice
hxxps://revenue.payfgm[.]cc/notice
hxxps://revenue.payfkv[.]cc/notice
hxxps://revenue.paygaa[.]cc/notice
hxxps://revenue.payhqe[.]cc/notice
hxxps://revenue.payidx[.]cc/notice
hxxps://revenue.payjjt[.]cc/notice
hxxps://revenue.payjok[.]cc/notice
hxxps://revenue.paykah[.]cc/notice
hxxps://revenue.paykdr[.]cc/notice
hxxps://revenue.paylsn[.]cc/notice
hxxps://revenue.paymnk[.]cc/notice
hxxps://revenue.paymtj[.]cc/notice
hxxps://revenue.paynds[.]cc/notice
hxxps://revenue.payono[.]cc/notice
hxxps://revenue.payque[.]cc/notice
hxxps://revenue.payquh[.]cc/notice
hxxps://revenue.payryc[.]cc/notice
hxxps://revenue.paysbv[.]cc/notice
hxxps://revenue.paytia[.]cc/notice
hxxps://revenue.payvem[.]cc/notice
hxxps://revenue.payvik[.]cc/notice
hxxps://revenue.paywar[.]cc/notice
hxxps://revenue.payyks[.]cc/notice
hxxps://revenue.payzlr[.]cc/notice

And yet another domain pattern, also registered at Dominet (HK) Limited and also hiding behind Cloudflare uses this pattern: 

hxxps://revenue.paybds[.]cc/notice
hxxps://revenue.paydjr[.]cc/notice
hxxps://revenue.paydqo[.]cc/notice
hxxps://revenue.payeoc[.]cc/notice
hxxps://revenue.payfgm[.]cc/notice
hxxps://revenue.payfkv[.]cc/notice
hxxps://revenue.paygaa[.]cc/notice
hxxps://revenue.payhqe[.]cc/notice
hxxps://revenue.payidx[.]cc/notice
hxxps://revenue.payjjt[.]cc/notice
hxxps://revenue.payjok[.]cc/notice
hxxps://revenue.paykah[.]cc/notice
hxxps://revenue.paykdr[.]cc/notice
hxxps://revenue.paylsn[.]cc/notice
hxxps://revenue.paymnk[.]cc/notice
hxxps://revenue.paymtj[.]cc/notice
hxxps://revenue.paynds[.]cc/notice
hxxps://revenue.payono[.]cc/notice
hxxps://revenue.payque[.]cc/notice
hxxps://revenue.payquh[.]cc/notice
hxxps://revenue.payryc[.]cc/notice
hxxps://revenue.paysbv[.]cc/notice
hxxps://revenue.paytia[.]cc/notice
hxxps://revenue.payvem[.]cc/notice
hxxps://revenue.payvik[.]cc/notice
hxxps://revenue.paywar[.]cc/notice
hxxps://revenue.payyks[.]cc/notice
hxxps://revenue.payzlr[.]cc/notice


refundfg[.]cc was actually a State of Florida tax refund scam, began about 11 days ago.  That campaign differed from this one in that it was hosted openly at TENCENT (AS132203, IP: 170.106.160.91) and shifted to using a different domain pattern: 
revenue.refuAXCV[.]cc
revenue.refuREWJ[.]cc
revenue.refuDZSA[.]cc

pivoting on that IP address, we can use Zetalytic's ZoneCruncher to look at the passive DNS and find many other domains.  Our TenCent phisher who is doing the New York Tax phish is clearly also doing Pennsylvania, and Minnesota! The Passive DNS also shows us other host and domain patterns for New York. 



Sunday, September 14, 2025

Indian Call Center Scammers partner with Chinese Money Launderers

 


At the end of August 2025, The US Attorney's office in San Diego announced four indictments against members of a Chinese organized crime ring that stole at least $65 million from thousands of older Americans.  The case was notable because the US Attorney credited two YouTube channels with the leads that led to 25 arrests so far in California, New York, Texas, and Michigan. 

When we see 25 Chinese arrests, it might be tempting to think this is all Chinese Organized Crime, but those who actually watch the videos will realize that's not the case.  The referenced videos are from late 2020 and early 2021 and each started with Scammer Payback (Pierogi) responding to a refund scam.

Indian Call Center operators refer to this type of "lead generation" as "email blasting" and we have tens of thousands of example posts from Facebook groups offering the "service" of sending bogus Microsoft Defender emails, claiming that the victim's credit card is being charged and offering a telephone number to dispute the charge. The ads for this service in Tech Support Facebook groups have been constant for years, including ads as recently as this week: 


A typical "Microsoft Defender Refund" from this time period looked like this: 


We've called dozens of these numbers and they all follow a similar script, they convince the caller to allow remote control to their computer to assist them with the "refund." We often feed a Virtual Machine to the scammers and use it to help us understand what remote control tool they are using and where it is hosted.  But Scammer Payback goes quite a bit further! 

When Pierogi received the numbers from a similar call center scam, he called the number.  His video makes clear that the scammers he was communicating with were speaking Hindi to one another. He not only lets the remote control happen, but he helpfully has a bank account open.  The scammers see the millions of dollars available and can't help themselves.  He is a juicy target!
Scammer Payback: https://www.youtube.com/watch?v=hrLZbc-Rfbo

The scammers have Pierogi type in his own refund amount - but they alter it to make it appear that he typed too many digits resulting in a much larger than intended refund.  Then they demand that he withdraw the difference in cash and ship it back to "them."

Being a very compliant victim, Scammer Payback agrees immediately, taking down the address and agreeing to send the package of cash "overnight delivery." At this point, Pierogi engages the Trilogy media team. Trilogy agrees to take their camera crew to the pick up site to find out who is on the other end of the package. 

Trilogy Media: https://www.youtube.com/watch?v=in_Y5q_-F2Y

But in three out of three cases where Pierogi uses Trilogy to deliver a cash package, the package is being sent to a young Chinese person who is at an Air BNB that has been rented for a very short time period. 

We actually have seen this model in other cases ... in 2022, we write about the case of Jianjie Liu on this blog in a post called "Chinese Call Center Runner Pleads Guilty in Georgia."  


Jianjie Liu did cash pickups for a wide variety of scams, including Grandparent scams, Inheritance scams, and Government Grant Scams.  She was actually arrested in a case involving Walmart Gift Cards that led to the discovery of 718 Gift Cards in her vehicle. In one case almost exactly like those above, Liu was sent a $20,000 Cashier's check after someone processing a $555 refund was accidentally refunded $20,555 and had to send the difference back to the scammers.  The check was made payable to a shell company in Georgia controlled by Liu.

Where do these Chinese agents doing the cash, check, and gift card payment come from? Recently it is one of the most popular "Crime As A Service" offerings from the various Chinese Guarantee Syndicates.  Each of the Guarantee Syndicates has a menu of vendors who have made a large deposit in USDT in order to have the right to sell their services there.  This category is usually called some variation of "Collection Services." 

You may have heard of "Huione Pay" which is generally considered the largest of the Chinese Guarantee Syndicates.  FinCEN took action, with an announcement that "Cambodia-based Huione Pay" is a money laundering concern, and proposing new Rule-making calling them a "Primary Money-Laundering Concern" to combat this type of cybercrime.  After this announcement, Huione migrated most of their vendors over to a former competitor, Tudou Danbao (which means "Potato Guarantee.")

The "Buy and Sell" channel for Potato currently has 130,000 subscribers, while one of their primary channels has 209,000 subscribers.  Category 2 on their vendor menu is "Collection Services" which currently has 656 vendors who have paid deposits between 15,000 USDT and 259,000 USDT to have their services recommended and advertised by the new Guarantee Syndicate.  These are the teams that are offering cash pickup services across the United States.

(findings from non-profit Intelligence for Good)

Many other Guarantee Syndicates have dozens to hundreds of similar vendors in their respective Collection Services vendor category.  Here is a typical ad, boasting of the cities where the vendor maintains teams of workers, ready to pick up packages: 



The US Financial Crimes Enforcement Network (FinCEN) has issued two recent reports about Chinese Money Laundering Networks.  One is an advisory regarding the use of Chinese Money Laundering Networks by drug cartels from Mexico.  The other has detailed analysis on several different models used by Chinese Money Laundering networks.


Several "Red Flags" are shared as advice to Financial Institutions to help them recognize CMLO behaviors that should be reported via Suspicious Activity Reports: 









Friday, September 12, 2025

Chinese Guarantee Syndicates and the Fruit Machine

When I was speaking to a group of Bank Security people in New York City yesterday, I mentioned "machine rooms" -- which are rooms full of Apple iPhones that are used to send iMessage phishing spam. Someone in the audience asked "Where would they get that many phones?"

The kids like to use the acronym "IYKYK" (If You Know You Know).  I learn new IYKYK phrases in Chinese Telegram every day. 

Today's new favorite phrase? 水果机 - Shuǐguǒ jī - "Fruit machine." 

 Example usage: 🔥低价出正品水果机 ("Genuine fruit machines at low prices") 

Fruit machine is coded language for Apple iPhones.

Huione Pay Advertisements for iPhone Smugglers

This advertiser pays HuionePay's Haowang Guarantee for the right to share an ad for their group once each hour in Huione, their highest rate, so that one line advertisement is posted 24 times per day to Haowang Guarantees "buy and sell" group. 

What? You thought Telegram had banned HuionePay? hahahahahaha ... but they do try to hide their traffic by rebranding their "Crime As A Service" vendors to be "Potato Guarantee" rather than Haowang Guarantee.


Group: "Yongle smuggles Apple phones"
The Chinese characters above the "danbao" spell "Potato" (tǔ dòu)
The Chinese characters below "danbao" are "Guarantee" (dān bǎo)

Links shared by this advertiser go to a 38,438 member "Potato Guarantee" group called "Yongle smuggles Apple phones" and share that Yongle has deposited "208,000 USDT" in order to insure that your transactions are safe. (The "Trust Model" of the Chinese Guarantee Syndicates is that vendors make a deposit to be listed in the vendor directory and the Syndicate promises that any transaction up to the level of the deposit will be backed by the Syndicate should anything go wrong.)

(Google translated)

The welcome message for the group says:

"Various models of iPhone are available, all smuggled into the country as brand new, unopened, and unactivated official Chinese versions, suitable for personal use or resale." They go on to say that your phone will be delivered within 72 hours and that if it is shown to be used, they will refund 10x your purchase price!

Another September ad using the "Fruit machine" language in a major HuionePay group also now goes to a "Potato Guarantee" group with 12,154 members. (Group 2851, with a 38,000 USDT Deposit) The translated "welcome" message when joining the group calls the group "Xili Smuggles mobile phones and digital products" and promises "Various models of iPhone are available, all smuggled into the country as brand new, unopened, and unactivated national versions, suitable for personal use or resale."

Group: "Xili Smuggles Mobile Phones and Digital Products"

Xili, who prefers to call himself "Heineken," is currently taking deposits for iPhone 17s. He also will throw in an Apple watch if you pay 1000 Yuan extra. Currently he charges 5999 Yuan for an iPhone 16 ProMax 1TB, or approximately $850. 

Xili / Heineken's most recent advertisement

If that whole thing sounds insane, I would encourage you to read the book "Apple in China" by Patrick McGee. Smuggling iPhones is an EXTREMELY lucrative organized crime business in China!

There are of course many more Guarantee Syndicates, with many thousands of vendors who have paid to advertise their "Crime As A Service" offerings, from Gift Card and Cash Pickups, SMS/iMessage/RCS Phishing, Credit Card Theft, Trade-based Money Laundering and anything else you can imagine, from Human Trafficking to Cigarette smuggling.  

Here are a few that we are tracking ... 

#HuionePay #CMLO #Apple #iPhones #Guarantee #Danbao #Haowang #iMsgSpam #SMS #Smishing

Wednesday, August 06, 2025

Project Red Hook: Chinese Gift Card Fraud at Scale



Project Red Hook is a Homeland Security Investigations operation examining how Chinese Organized Crime is committing wholesale Gift Card Fraud by using Chinese illegal immigrants to steal gift cards, reveal their PIN, reseal the cards, and return them to store racks.  When the card is later purchased and activated, operators are standing by to quickly drain the card before the customer can use it. How many cards are we talking about?  More than $1 Billion worth! 

Here are a few cases of interest to me - especially the first one! 

Birmingham, Alabama 

https://www.justice.gov/usao-ndal/pr/chinese-nationals-charged-illegally-possessing-counterfeit-and-unauthorized-gift-cards

25JUN2025 - the Hoover Alabama Police Department put out a BOLO for two Asian males in a gray Lexus SUV with California tag DE53Y62 who were switching gift cards in racks at local CVS stores.  Jiadong Cao, 36, and Xuejun Zheng, 48, were stopped and arrested the following day in Pelham, Alabama and found to possess more than 5,000 gift cards.  Portions of the gift card numbers had been destroyed on the cards, which would allow the cards to be activated at the register, but not used by the customer who purchased them. 300 altered cards for Home Depot, Amazon, Sephora, Macy's and Nike were found in their car.  Home Depot reviewed their cards and confirmed they had not been sold.


The Federal criminal complaint was written up by a former student of mine!  USSS Special Agent Scott Easterwood! Jiadong Cao is a Chinese citizen who entered the US in September 2024 and is illegally in the country now.  Xuejun Zheng also entered the US in September and has filed for asylum in the US. In the CVS store that started this investigation, they had added altered gift cards to the rack, including six Nike cards, ten Macy's cards, and nine Best Buy cards. 

Louisville, Kentucky

https://www.wlky.com/article/men-arrested-gift-card-scam-louisville-millions-lost/62673181

19OCT2024 - Kroger security personnel observed Chaoming Lin placing gift cards back on a rack at a store on North Hubbards Lane. He was stopped shortly thereafter by St. Matthews Police, who found him in the car with Zhiqiang Huang.  Around 5,000 gift cards were found in a search of the vehicle, with at least 2,000 appearing to have been altered. That same day, Kroger loss prevention reported another instance and that an Asian man was seen leaving in a black Dodge Charger.  That car was also stopped with Tianlong Chen and Huixing Yu in the car with several cell phones and 658 gift cards in the car.   These four had hit stores in Ohio, Pennsylvania, and New York before being arrested in Kentucky. 






St. Matthew's Police chief Barry Wilkerson said the gift cards they recovered were worth at least $1 million. Tianlong Chen entered a guilty plea on 11JUL2025 and will remain in custody until sentencing on 16OCT2025. 


Gainesville, Florida

https://www.documentcloud.org/documents/24536188-gainesville-case-detailed-arrest-report/

24AUG2024 - The Alachua County Sheriff's office pulled over a Hertz rental vehicle being driven by Cheng Li, 25, with female passenger Jiaxin Jiang, 24.   The car was rented by Jiang despite him only possessing a New York Learner's permit.  After a narcotics K-9 hit on the car, the car was searched and found to contain 1,764 gift cards from Apple, Target, Visa, Mastercard, and American Express.  A GPS review provided by Hertz confirmed that the pair had left Long Island, New York, stopping at two Target stores in Laurel, Virginia, ten Target stores in the Duluth/Atlanta Georgia area, two Target stores in Knoxville, Tennessee, and a Target store in Johnson City, North Carolina before being arrested after a stop at the Target store in Gainesville, Florida.  Their mapping software indicated they were headed to a Target store in Ocala, Florida next. 


A review of Cheng's cell phones (after a search warrant) revealed that he had been involved in "Target fraud" chats on WeChat since as far back as December 2022. Ledgers on Jiang's computer showed they had been collecting gift card numbers and their associated PINs going back as far as 09AUG2022. WeChat groups retrieved by the phone show groups with as many as 1558 messages and 257 photos with some groups having as many as eleven members who all seemed involved in the same types of activities. 

The Chinese language website "https://www.uscardforum.com/t/topic/321165" shared a Chinese version of the traffic stop, complete with opening the trunk and finding the cards! 

The couple tell the police they are in Florida because they wanted to see a crocodile! 

 (Watch on YouTube here: https://www.youtube.com/watch?v=YChGKg2KrDo - jump to 16:40 for the "trunk reveal." ) 

Ventura, California

15MAY2024 - Ventura County detectives are part of the Ventura County Organized Retail Theft Task Force (VCORTTF).  They were operating a "blitz" against organized retail crime, deploying detectives in coordination with loss prevention specialists in retail stores. when they arrested Tingxiang Yang, 39, and Lingyu Chen, 35.  They were in possession of 800 gift cards stolen from a Moorpark Target store. They were released after posting $20,000 bail. 


Ocala, Florida

 https://www.ice.gov/news/releases/chinese-national-pleads-guilty-gift-card-fraud-scheme

17OCT2023 - a police officer in Ocala, Florida arrested Donghui Liao, age 32.  Liao was observed taking gift cards from his black shoulder back and placing those gift cards on a gift card display in a Target store. Seventy-one cards on the rack were found to have been altered.  The cards had been shop-lifted, scratched to reveal their PIN, "re-silvered" so that they did not appear to have been scratched, and then returned to card racks in stores.  Liao was found to be on surveillance camera imagery at stores in Ohio, Georgia, North Carolina, and Florida. 


When police searched his car, they found 6,032 additional gift cards with a face value of $1,886,000! 


Donghui was sentenced to 33 months in prison with 3 years supervised release to follow.