logo

Cross-Border Cryptocurrency Investment Scam Leveraging Social Messaging Channels and Fake Regulatory Credentials

ID: 26a7de84-8284-58c6-8ca7-6ef9a02c6007

STIX ID: report--26a7de84-8284-58c6-8ca7-6ef9a02c6007

Feed Name: CloudSEK Blog

Threat Score
75/100

Date Published: 2026-02-02

Date Updated: 2026-04-27

...
...

**Executive Summary:** CloudSEK identifies ZHGUI Cryptocurrency Ltd. as a coordinated mirror-exchange scam targeting Mandarin-speaking retail investors in Southeast Asia (notably Malaysia), using cloned domains, fake trading dashboards, invitation-only onboarding, and Udesk-style KYC harvesting to collect funds and personal data; on-chain TRON (TRC20) analysis reveals an aggregated laundering pipeline (RazorPay and ZHGUI routing wallets) that forwards USDT to major centralized exchanges, and the operation leverages self-submitted FinCEN MSB listings, paid PR, social media, WhatsApp recruitment, and a previously published iOS app to create false legitimacy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.