Retiree loses over RM337,000 in Facebook investment scam
Authorities warn public to verify financial transactions as pensioner duped by fake online investment
简体中文
繁體中文
English
Pусский
日本語
ภาษาไทย
Tiếng Việt
Bahasa Indonesia
Español
हिन्दी
Filippiiniläinen
Français
Deutsch
Português
Türkçe
한국어
العربية
Abstract:A new Binance email scam tricks users with a fake Trump Coin app that installs ConnectWise RAT malware. Learn how cybercriminals exploit trends to steal data fast.

A fraudulent email scam masquerading as the prominent cryptocurrency exchange Binance is duping naive people into a trap. These bogus communications, which promise access to a fictitious TRUMP coin, trick users into downloading malware masquerading as a desktop program. Cybersecurity researchers at Cofense, who discovered the scheme, warn that this fraud installs a remote access tool (RAT) called ConnectWise, giving attackers total control of affected devices in minutes.
How the Scam Unfolds
The campaign begins with emails purporting to be from “Binance,” luring recipients with news of a newly released Trump-themed cryptocurrency. These emails include a link to a phony Binance website that is meticulously designed to imitate the genuine thing. The site imitates official logos and even displays security alerts to lure people into believing it. However, instead of giving Bitcoin, it directs visitors to download “Binance Desktop,” a malicious package that launches the ConnectWise RAT.
According to a recent blog post by Cofense, the bogus emails and websites do not directly replicate Binance's official pages but instead artfully blend actual photos and design components to appear convincing. The scammers go the extra mile by including a “risk warning” statement, a subtle touch that adds to the image of credibility. The download URL leads to a Russian-hosted site, Binance-web3comru, which hosts the virus. Two other rogue websites, klclick2com, and shopifycoursesstore, have been linked to this scheme.

Unlike other RAT operations, in which hackers bid their time, these fraudsters do not squander any. Cofense researchers discovered that attackers connect to infected devices in less than two minutes after infection. Once inside, hackers rummage through browsers like Microsoft Edge, manually extracting cached passwords and other data, outperforming the malware's built-in thieving skills.
Why This is a Big Deal
Jason Soroko, a Senior Fellow at Sectigo, explained why these frauds work so successfully. He pointed out that hackers frequently capitalize on heated subjects to entice their victims. By linking their scams to current events, such as the excitement around Trump-related cryptocurrencies, they make their bait appear urgent and credible, encouraging consumers to act without hesitation.
“Topical events serve as fertile ground for social engineering, offering attackers a ready-made script that exploits real-time urgency and widespread public attention,” Jason told me. “By aligning phishing messages and malicious campaigns with trending news or current events, cybercriminals enhance credibility and evoke strong emotional reactions, prompting hasty actions from potential victims.”
Scammers Keep Cashing In on Trump's Hype
This is not the first time scammers have targeted Trump's cryptocurrency companies. In July 2024, they circulated false information about Trump's assassination in order to sell cryptocurrency. A year earlier, in July 2023, a phishing wave targeted his supporters with bogus websites designed to steal Bitcoin donations. More recently, in September 2024, hackers attacked Trump's new digital trading cards, launching phishing sites and false domains to steal personal information.
The Binance email scam that took advantage of the “TRUMP coin” craze demonstrates how smart cybercriminals can be, combining real-world trends with sophisticated methods to catch people off guard. With attackers moving quickly and adopting famous identities such as Binance, being vigilant is more important than ever. Always double-check URLs and downloads, especially when claims of rapid cryptocurrency riches appear.

Disclaimer:
The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.

Authorities warn public to verify financial transactions as pensioner duped by fake online investment

Failed to withdraw funds from the BDSWISS trading account despite multiple attempts? Did the broker reject your fund withdrawal application without any reason? Did the high slippage lead to massive capital losses? Was the customer support team far from ideal? Many traders have reported these issues online. In this BDSWISS review article, we have examined several such complaints against the forex broker.

When your capital is at risk, trust isn't just a feeling - it's something you can measure. For traders thinking about using the broker Evest, one question is impossible to avoid: Is Evest a trusted partner for your investments, or does it put your investments at serious risk? The answer to this important question, "Is Evest Safe or Scam?", isn't found in the company's ads. You find it by comparing what the broker officially says with the real, often worrying experiences of actual users. This review won't rely on guessing. Instead, we'll take a deep look at the broker's legal status and, more importantly, the number and types of real Evest complaints. Our research is based on public information, mainly from the worldwide broker research platform, WikiFX, to show the truth about Evest's reputation.

XPO Markets, a Comoros-based brokerage entity, is in the news for negative reasons. These include the alleged INR 3,100 crore fund scam complaint filed by 3 lakh Indians in November 2025. Such a scam puts a serious question mark on the authenticity of this forex broker. In this XPO Markets review article, we have highlighted the million-dollar scam along with the risk parameters associated with this broker.