Money mule networks have evolved from simple recruitment schemes into highly organized Mule-as-a-Service (MaaS) operations.
Threat actors are increasingly exploiting Telegram channels and dark web forums to sell verified bank accounts and fintech wallets.
According to recent threat intelligence from KELA, cybercriminals are building resilient laundering infrastructures using stolen identities, AI-assisted onboarding, and compromised accounts to monetize ransomware, phishing, and fraud campaigns.
Telegram Markets Verified Accounts
The traditional three-stage money laundering process placement, layering, and integration has been supercharged by digital financial platforms. Today, MaaS providers offer specialized infrastructure directly to cybercriminals.
These syndicates operate centralized management panels via APIs, enabling rapid, automated fund dispersal that bypasses traditional Anti-Money Laundering (AML) triggers.

A major driver of this evolution is the deployment of artificial intelligence to bypass Know Your Customer (KYC) protocols at an unprecedented scale.

Threat actors leverage several advanced techniques to provision these fraudulent accounts:
- Synthetic identities are created by combining stolen Personally Identifiable Information with AI-generated faces, names, and addresses.
- Deepfake injection bypasses liveness checks by feeding synthetic video streams directly into a mobile device’s camera pipeline.
- Agentic AI utilizes automated bots to perform low-risk “warming” transactions, such as paying utility bills, to build algorithmic trust before executing large illicit transfers.
- AI-assisted document forgery generates high-resolution identity documents that replicate complex security features to bypass Optical Character Recognition validation.

These AI-driven tactics allow criminals to mass-produce “pre-warmed” accounts with lower fraud risk profiles. These verified accounts are subsequently packaged and sold on Telegram to other threat actors seeking reliable cash-out avenues.
While MaaS is a global threat, Latin America has rapidly emerged as a primary hotspot due to the adoption of real-time payment systems.
Brazil’s PIX network has facilitated the rise of “Contas Laranja” (Orange Accounts), with nearly 250,000 Telegram messages tracked by KELA discussing the rental or sale of these accounts.
Similarly, threat actors actively exploit Argentina’s CBU/CVU digital wallet infrastructure and Colombia’s peer-to-peer payment apps to move funds across borders with minimal friction.
According to kelacyber research, financial institutions must shift from reactive transaction monitoring to proactive, identity-focused intelligence.
Security teams should implement the following mitigation strategies to counter modern MaaS ecosystems:
- Enhance liveness verification by upgrading security controls to detect deepfake video injection and AI-driven voice cloning during onboarding.
- Deploy behavioral analytics to identify automated, low-value transaction patterns designed to simulate legitimate user activity and “warm” new accounts.
- Proactively monitor Telegram channels and dark web forums for emerging KYC-bypass manuals, AI tradecraft, and account provisioning advertisements.
- Adapt transaction-monitoring algorithms to detect predictive smurfing, in which AI dynamically adjusts transfer sizes to remain just below regulatory reporting thresholds.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.