logo

Mobile Phishers Target Brokerage Accounts in ‘Ramp and Dump’ Cashout Scheme

ID: fad74dc7-0e15-568c-9fd2-b093867a5684

STIX ID: report--fad74dc7-0e15-568c-9fd2-b093867a5684

Feed Name: Krebs on Security

Threat Score
70/100

Date Published: 2025-08-15

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Researchers observed China-based phishing kit vendors selling advanced mobile phishing tools on Telegram that steal credentials and phish one-time codes to enroll payment cards into attackers’ mobile wallets and to hijack brokerage accounts; attackers then use multiple compromised brokerage accounts in coordinated 'ramp-and-dump' trades to inflate and dump penny/IPO stocks, causing investor losses. The report notes active exploitation (FBI/FINRA attention), seller demonstrations (e.g., “Outsider”), use of phishable MFA channels, and operational scale including bulk phone sales and human operators, with some banks adopting stronger wallet enrollment controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.