Banners, Bots and Butchers: The AI-Driven Long Con in Asia
This intelligence report details a hybrid cryptocurrency investment scam campaign targeting users in Asia, particularly Japan. The scam combines malvertising techniques to attract victims with pig butchering tactics using AI-powered chatbots for sustained engagement. Victims are lured through social media ads impersonating financial experts, directed to lure websites, and then to messaging apps where automated bots manipulate them into making increasingly large investments. The campaign uses over 23,000 domains, many generated algorithmically, and shows signs of expanding globally. This approach represents a scalable, automated evolution of traditional investment fraud methods, potentially transforming labor-intensive scams into more efficient operations.
AI Analysis
Technical Summary
The campaign titled "Banners, Bots and Butchers: The AI-Driven Long Con in Asia" represents an evolution in cryptocurrency investment scams by combining malvertising and AI-driven social engineering. Initially, victims are targeted through social media advertisements that impersonate credible financial experts, enticing users to visit lure websites. These websites serve as gateways to messaging platforms where AI-powered chatbots engage victims in sustained conversations, employing pig butchering tactics—gradually building trust and coaxing victims into making progressively larger cryptocurrency investments. The campaign's infrastructure includes over 23,000 domains, many generated algorithmically, enabling rapid domain rotation to evade detection and takedown efforts. This automation reduces the need for human operators, increasing scalability and operational efficiency. The campaign is currently concentrated in Asia, particularly Japan, but indicators suggest expansion beyond this region. The threat does not exploit software vulnerabilities but relies on social engineering and deception. No known exploits or CVEs are linked to this campaign. The use of AI chatbots for long-term engagement marks a significant shift in investment fraud methodology, potentially increasing victim losses and complicating detection.
Potential Impact
Organizations and individuals face significant financial losses due to this scam, especially those involved or interested in cryptocurrency investments. The campaign's use of AI chatbots for prolonged engagement increases the likelihood of victims investing large sums over time. Financial institutions and cryptocurrency exchanges may experience indirect impacts such as increased fraud-related inquiries, chargebacks, and reputational damage. The large-scale domain generation complicates detection and blocking efforts, potentially allowing the scam to reach a broad audience. The psychological manipulation involved can lead to long-term trust erosion in legitimate financial services and platforms. Additionally, the campaign's expansion beyond Asia could expose global markets to similar risks. Regulatory bodies may face challenges in tracking and prosecuting perpetrators due to the automated and distributed nature of the infrastructure. Overall, the threat undermines trust in cryptocurrency markets and digital financial services.
Mitigation Recommendations
1. Implement advanced domain and URL filtering solutions that incorporate threat intelligence feeds to block access to known malicious and algorithmically generated domains associated with this campaign. 2. Deploy AI and machine learning-based detection systems to identify anomalous chatbot behaviors and suspicious messaging patterns on communication platforms. 3. Conduct targeted user awareness campaigns focusing on the risks of cryptocurrency investment scams, emphasizing the identification of impersonation and social engineering tactics. 4. Collaborate with social media platforms to identify and remove malvertising campaigns and fake profiles impersonating financial experts. 5. Encourage financial institutions and cryptocurrency exchanges to monitor for unusual transaction patterns indicative of scam-related activities and to provide clear reporting channels for suspected fraud. 6. Utilize multi-factor authentication and transaction verification processes to reduce the risk of unauthorized or coerced investments. 7. Establish rapid takedown procedures for newly identified malicious domains to disrupt the campaign's infrastructure. 8. Monitor messaging app ecosystems for AI chatbot abuse and work with providers to implement stricter controls on automated accounts. 9. Share threat intelligence across regional and international cybersecurity communities to enhance detection and response capabilities.
Affected Countries
Japan, South Korea, China, Singapore, Taiwan, Hong Kong, Malaysia, Thailand, Vietnam, Indonesia
Indicators of Compromise
- domain: 7973268.top
- domain: 8jz2x.icu
- domain: aopmbxeqax.click
- domain: btedsrr.icu
- domain: fgynfgi.buzz
- domain: fhysgth.sbs
- domain: ghmfg.sbs
- domain: gnlaoprs.click
- domain: googlenames.top
- domain: hrdfsetsdf.sbs
- domain: koaliuehudrt.sbs
- domain: kpusnenvcg.buzz
- domain: lgsmjhsb.buzz
- domain: oiajdng.click
- domain: oslddjb.buzz
- domain: r2th4.icu
- domain: safesecurea.sbs
- domain: stock-analysis06.buzz
- domain: ttrvsgg.icu
- domain: ttrvsii.icu
- domain: ttrvsrr.icu
- domain: vbmuakf.click
- domain: xhlch.top
- domain: xqeha.icu
- domain: ydfshans.click
- domain: yhdakgjd.top
- domain: youtubefind.com
- domain: youtubefind.top
Banners, Bots and Butchers: The AI-Driven Long Con in Asia
Description
This intelligence report details a hybrid cryptocurrency investment scam campaign targeting users in Asia, particularly Japan. The scam combines malvertising techniques to attract victims with pig butchering tactics using AI-powered chatbots for sustained engagement. Victims are lured through social media ads impersonating financial experts, directed to lure websites, and then to messaging apps where automated bots manipulate them into making increasingly large investments. The campaign uses over 23,000 domains, many generated algorithmically, and shows signs of expanding globally. This approach represents a scalable, automated evolution of traditional investment fraud methods, potentially transforming labor-intensive scams into more efficient operations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The campaign titled "Banners, Bots and Butchers: The AI-Driven Long Con in Asia" represents an evolution in cryptocurrency investment scams by combining malvertising and AI-driven social engineering. Initially, victims are targeted through social media advertisements that impersonate credible financial experts, enticing users to visit lure websites. These websites serve as gateways to messaging platforms where AI-powered chatbots engage victims in sustained conversations, employing pig butchering tactics—gradually building trust and coaxing victims into making progressively larger cryptocurrency investments. The campaign's infrastructure includes over 23,000 domains, many generated algorithmically, enabling rapid domain rotation to evade detection and takedown efforts. This automation reduces the need for human operators, increasing scalability and operational efficiency. The campaign is currently concentrated in Asia, particularly Japan, but indicators suggest expansion beyond this region. The threat does not exploit software vulnerabilities but relies on social engineering and deception. No known exploits or CVEs are linked to this campaign. The use of AI chatbots for long-term engagement marks a significant shift in investment fraud methodology, potentially increasing victim losses and complicating detection.
Potential Impact
Organizations and individuals face significant financial losses due to this scam, especially those involved or interested in cryptocurrency investments. The campaign's use of AI chatbots for prolonged engagement increases the likelihood of victims investing large sums over time. Financial institutions and cryptocurrency exchanges may experience indirect impacts such as increased fraud-related inquiries, chargebacks, and reputational damage. The large-scale domain generation complicates detection and blocking efforts, potentially allowing the scam to reach a broad audience. The psychological manipulation involved can lead to long-term trust erosion in legitimate financial services and platforms. Additionally, the campaign's expansion beyond Asia could expose global markets to similar risks. Regulatory bodies may face challenges in tracking and prosecuting perpetrators due to the automated and distributed nature of the infrastructure. Overall, the threat undermines trust in cryptocurrency markets and digital financial services.
Mitigation Recommendations
1. Implement advanced domain and URL filtering solutions that incorporate threat intelligence feeds to block access to known malicious and algorithmically generated domains associated with this campaign. 2. Deploy AI and machine learning-based detection systems to identify anomalous chatbot behaviors and suspicious messaging patterns on communication platforms. 3. Conduct targeted user awareness campaigns focusing on the risks of cryptocurrency investment scams, emphasizing the identification of impersonation and social engineering tactics. 4. Collaborate with social media platforms to identify and remove malvertising campaigns and fake profiles impersonating financial experts. 5. Encourage financial institutions and cryptocurrency exchanges to monitor for unusual transaction patterns indicative of scam-related activities and to provide clear reporting channels for suspected fraud. 6. Utilize multi-factor authentication and transaction verification processes to reduce the risk of unauthorized or coerced investments. 7. Establish rapid takedown procedures for newly identified malicious domains to disrupt the campaign's infrastructure. 8. Monitor messaging app ecosystems for AI chatbot abuse and work with providers to implement stricter controls on automated accounts. 9. Share threat intelligence across regional and international cybersecurity communities to enhance detection and response capabilities.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.infoblox.com/blog/threat-intelligence/banners-bots-and-butchers-an-automated-long-con-targeting-japan-asia-and-beyond"]
- Adversary
- null
- Pulse Id
- 69972ba50be84a620b567652
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domain7973268.top | — | |
domain8jz2x.icu | — | |
domainaopmbxeqax.click | — | |
domainbtedsrr.icu | — | |
domainfgynfgi.buzz | — | |
domainfhysgth.sbs | — | |
domainghmfg.sbs | — | |
domaingnlaoprs.click | — | |
domaingooglenames.top | — | |
domainhrdfsetsdf.sbs | — | |
domainkoaliuehudrt.sbs | — | |
domainkpusnenvcg.buzz | — | |
domainlgsmjhsb.buzz | — | |
domainoiajdng.click | — | |
domainoslddjb.buzz | — | |
domainr2th4.icu | — | |
domainsafesecurea.sbs | — | |
domainstock-analysis06.buzz | — | |
domainttrvsgg.icu | — | |
domainttrvsii.icu | — | |
domainttrvsrr.icu | — | |
domainvbmuakf.click | — | |
domainxhlch.top | — | |
domainxqeha.icu | — | |
domainydfshans.click | — | |
domainyhdakgjd.top | — | |
domainyoutubefind.com | — | |
domainyoutubefind.top | — |
Threat ID: 69974c64d7880ec89b0185a0
Added to database: 2/19/2026, 5:46:12 PM
Last enriched: 2/19/2026, 6:01:24 PM
Last updated: 4/6/2026, 4:52:05 AM
Views: 149
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.