Scammers are using WhatsApp groups to turn ordinary investors into an unwitting buying force. The operation does not need a hacked trading account or a stolen card.
Instead, it persuades people to place real trades through legitimate brokerages, then leaves them carrying the losses when the price collapses. The campaigns pair short-lived deepfake advertisements with messages that promise timely stock tips.
People who click are filtered by location and steered into groups led by a convincing “head analyst,” who gives members a small-cap share, a limit price and a tempting target. The apparent advice is actually coordinated market manipulation.
Analysts at Group-IB identified the activity while examining two organised investment-fraud operations, GoldBull and CoinLure.
Group-IB said in a report shared with Cyber Security News (CSN) that fraud is hardest to stop when a victim has been groomed into authorising the payment or trade themselves.
The findings show how a social-engineering scam can exploit trusted apps, brokerages and exchanges without directly breaking into them.
They also show why the response cannot stop at a single suspicious transfer: the useful clues sit across advertisements, domains, contact details, accounts and repeated behaviour, much like patterns seen in investor fraud network attacks.
WhatsApp Groups Drive Real Stock Pumps
GoldBull starts with advertisements that impersonate financial professionals using deepfake content.
Their limited online lifespan creates pressure to act before an offer disappears. Geo-targeted redirects then funnel prospective victims into WhatsApp communities, where an analyst persona presents an apparently exclusive, tightly timed opportunity.
Members are told to buy a genuine small-cap stock through their usual broker and submit proof that they did so.
.webp)
That instruction creates the buying volume the operators need. Two or three groups with roughly 1,000 participants can generate enough demand to move a thinly traded stock, placing an estimated $1.5 million to $3 million of victim money behind a campaign.
In one documented case, participants were instructed on 6 November 2025 to buy a NASDAQ-listed share at $24.79, with a target of $29.
The price later reached $27.87 on 9 December, a 12.4 percent gain. Operators sold their pre-positioned holdings at that point, while the promised target was never met.
By February, the same share traded at $14.27, 42 percent below victims’ entry point. The design relies on trust and speed, not a compromised brokerage.
Readers should treat rushed trading calls, celebrity-style ads and chat groups that demand purchase proof as warning signs, especially where alleged experts promise certainty. Similar bait techniques feature in deepfake investment scam campaigns.
Fake Platforms Expand the Network
The related CoinLure operation uses search-optimised pages, social advertisements and romance-scam grooming to bring people to fake investment platforms.
Victims encounter imitation registration, identity checks and trial funds before being offered tiered plans. The staged process makes a fraudulent service look familiar before it asks for more money.
When a customer seeks a withdrawal, the excuses arrive: minimum balances, supposed taxes or insurance fees worth 10 to 30 percent, forced upgrades, technical problems and eventual compliance freezes.
Some victims are approached again with a recovery offer that demands another upfront fee. No legitimate investment opportunity should require payment simply to release a customer’s own money.
Investigators linked one confirmed CoinLure platform to 208 domains using 23 shared templates, common hosting and repeated contact information.
That infrastructure points to estimated network revenue of $187 million. It also gives defenders a route to action: finding one fraudulent page can expose related ads, redirects and personas, an approach relevant to large fake news networks.
The report recommends looking beyond the final payment and connecting signals across institutions while protecting customer data.
Banks can watch for unusual changes in app use before large transfers, assess suspicious beneficiaries and devices against wider intelligence, and move quickly on evidence-backed takedowns.
For individuals, independently verify advisers, use official broker channels, reject guaranteed returns and never send fees to unlock a withdrawal.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC