Boxing Clever: Uncovering a $1M Task Scam Cluster Exploiting Major Brands

Aug. 26, 2025, 7:09 p.m.

Description

A sophisticated task scam cluster has been discovered, exploiting major brands like Delta Airlines, AMC Theatres, and Universal Studios. The scam uses API-driven templates and cryptocurrency payments, with over $1 million in attributable transactions. Victims are lured into 'earning' money by completing tasks such as booking flights. The scam requires initial cryptocurrency deposits to become a 'VIP' member. The infrastructure utilizes domains registered through Dominet, Alibaba Cloud's registrar, with a distinct registrant pattern. Multiple wallet addresses across different cryptocurrencies have been identified. The scam's configuration files reveal its adaptability across various brands and industries.

Date

  • Created: Aug. 26, 2025, 4:14 p.m.
  • Published: Aug. 26, 2025, 4:14 p.m.
  • Modified: Aug. 26, 2025, 7:09 p.m.

Indicators

  • universalstudioworksite.com
  • fp40.com
  • epicrecorlvip.com
  • deltaairlineivip.com
  • amctheatreilu.com
  • amblinil.com
  • all-accorli.com

Attack Patterns

Additional Informations

  • Aerospace
  • Technology
  • Media
  • Finance