Crypto Scams Sweep Asia, Blending Malvertising and Pig Butchering Tactics

Cybersecurity researchers are warning about a large-scale cryptocurrency fraud operation spreading across Asia, particularly Japan, that combines online advertising abuse with long-term social engineering.

The campaign combines malvertising malicious online advertisements with the so-called “pig butchering” investment scam model.

Investigators discovered thousands of suspicious domains after noticing abnormal DNS activity from Japanese internet users.

What initially appeared to be a typical fake trading platform turned out to be a hybrid operation designed to attract, manipulate, and financially drain victims over time. Individual losses have reportedly reached ¥10 million (about $63,000).

The attack begins with advertisements on social media platforms. The ads impersonate well-known financial experts or promote an advanced “AI investment algorithm.”

When users click the ad, they are redirected to a professional-looking website. Instead of asking for money immediately, the site guides victims to join conversations on legitimate messaging apps such as LINE, WhatsApp, or KakaoTalk.

In these chats, victims interact with supposed investment mentors, assistants, and student groups.

Researchers found many of these accounts were likely AI-assisted chatbots. They continuously engage victims, share fake profit screenshots, and tell fabricated success stories to build trust.

Hybrid use of malvertising and pig butchering (Source: infoblox)
Hybrid use of malvertising and pig butchering (Source: infoblox)

Over weeks or months, victims are persuaded to invest increasing amounts of money. Eventually, scammers request a final “release fee” to unlock profits that never actually exist.

A Scalable and Automated Fraud Ecosystem

Technical analysis identified more than 23,000 domains tied to the campaign. Many were generated using registered domain-generation algorithms, allowing criminals to create and rotate websites to avoid takedowns rapidly.

Some domains used random characters, while others mimicked trusted brands to appear legitimate.

The lure websites share identical layouts and messaging, suggesting a common scam kit or “fraud-as-a-service” platform used by multiple criminal groups.

Investigators also observed overlapping advertising trackers, infrastructure patterns, and messaging behavior across campaigns.

The structure of the scam is carefully designed so that victims believe they are acting voluntarily.

They click ads, initiate chats, and ask questions themselves, which reduces suspicion. In chat groups, participants receive constant engagement, rewards, and points-based incentives to keep them active.

Researchers who interacted directly with the scammers noticed conversations ran continuously across time zones and languages, strongly indicating automation.

Campaign-associated clusters comprised of infrastructure and domain nodes (Source: infoblox)
Campaign-associated clusters comprised of infrastructure and domain nodes (Source: infoblox)

Fast responses at all hours and repetitive dialogue further supported the use of AI-driven messaging systems.

Expanding Beyond Asia

Although Japan and South Korea are primary targets, the operation is expanding globally, with campaigns now appearing in English-, German-, and Spanish-speaking regions. Analysts detect thousands of new scam domains every month.

The hybrid approach dramatically increases efficiency. Malvertising provides scale and reach, while messaging apps deliver psychological manipulation and long-term trust building. By automating conversations, criminals can operate worldwide without large human teams.

Monthly distribution of second-level domain (SLD) registrations linked to these campaigns since January 2025 (Source: infoblox)
Monthly distribution of second-level domain (SLD) registrations linked to these campaigns since January 2025 (Source: infoblox)

Researchers warn that this model represents the next evolution of online financial fraud.

Unlike traditional scams, victims often believe they are participating in legitimate investments until the final payment request. By the time the deception is discovered, funds are unrecoverable.

According to Infoblox, security experts advise users to avoid investment offers on social media, verify financial advisors independently, and treat any request for upfront fees or private transfers as a strong indicator of fraud.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories