Scammers Orchestrate Stock Manipulation Schemes Using WhatsApp and Deepfakes
Cybercriminals are orchestrating sophisticated pump-and-dump stock schemes, leveraging WhatsApp groups and deepfake advertisements to manipulate millions of dollars in trades from unsuspecting investors.

Scammers are employing a novel strategy to execute pump-and-dump stock schemes, bypassing traditional hacking methods by manipulating ordinary investors into making trades themselves. These operations, identified by Group-IB and dubbed GoldBull and CoinLure, generate millions in victim trades by artificially inflating the prices of small-cap stocks.
The core of these scams lies in social engineering, utilizing trusted platforms like WhatsApp and legitimate brokerage services. Instead of directly breaching accounts, the attackers groom victims through convincing "head analyst" personas within private groups. These analysts provide seemingly expert advice, directing members to purchase specific small-cap stocks at a set price with a promised target, thereby creating artificial demand.
Group-IB's analysis highlights that fraud is most difficult to combat when victims willingly authorize their own transactions. The GoldBull campaign, for instance, begins with advertisements featuring deepfake content impersonating financial professionals. These ads create a sense of urgency, leading potential victims to geo-targeted WhatsApp groups. Once inside, members are instructed to buy a genuine stock through their own broker and provide proof of purchase, directly contributing to the stock's price manipulation.
These coordinated buying efforts can significantly impact thinly traded stocks. Group-IB estimates that just two to three groups with around 1,000 participants each can generate enough volume to move a stock, potentially placing $1.5 million to $3 million of victim money behind a single campaign. In one documented instance, a stock targeted by the scam saw a 12.4% gain based on victim trades, after which the operators sold their holdings, leaving victims with losses as the stock later plummeted.
The related CoinLure operation employs different tactics, using search-optimized pages, social advertisements, and romance-scam grooming to lure individuals to fake investment platforms. These platforms mimic legitimate services with staged registration processes, identity checks, and trial funds before pushing tiered investment plans. When victims attempt to withdraw funds, they are met with a barrage of excuses, including minimum balance requirements, fabricated taxes, insurance fees, forced upgrades, and technical issues, ultimately preventing any withdrawal.
Investigators linked one confirmed CoinLure platform to 208 domains, revealing a vast network with estimated revenues of $187 million. This extensive infrastructure provides a clear attack vector for defenders, as identifying one fraudulent page can lead to the discovery of related advertisements, redirects, and personas.
Group-IB recommends a multi-faceted approach to combating these schemes, emphasizing the need to look beyond the final transaction and connect signals across various institutions. Banks are advised to monitor for unusual app usage patterns before large transfers, assess suspicious beneficiaries and devices against threat intelligence, and act swiftly on evidence-backed takedowns.
For individuals, vigilance is key. Users should independently verify financial advisors, exclusively use official broker channels, be wary of guaranteed returns, and never send upfront fees to unlock their own funds. Recognizing rushed trading calls, celebrity-style advertisements, and chat groups demanding purchase proof are crucial early warning signs, especially when combined with promises of certainty.