Executive Summary
Threat actors exploit election season in the U.S. to target individuals with sensationalized claims about the electoral process, health misinformation, and fake investments. This leads to data exposure, financial losses, and eroded trust in institutions. Using social media platforms like Facebook, actors spread inflammatory messages to undermine election integrity. For example, an advertiser named “The Tech Prophet” spent over $7,000 on deceptive ads, reaching up to 150,000 viewers and funneling users to data-harvesting websites like “pro.insightandincome.com.”
Health misinformation ads, promoted via sites like “pro.joinhsi.com,” lure users with free subscriptions but redirect them to payment pages, impacting both finances and wellbeing. Additionally, AI-generated videos promoting fake government stimulus initiatives drive viewers to phishing sites like “prizestash.com,” with advertisers like "Liberty Giveaways" running over 290 misleading ads.
Threat actors also exploit cryptocurrency by creating fraudulent tokens mimicking political campaigns, particularly on the Solana network, leading to financial losses and regulatory concerns. Victims often face financial and emotional distress, with little chance of recovering funds.
This disinformation ecosystem impacts hundreds of thousands of U.S. users, resulting in millions in potential losses. A strong response is essential, including deepfake detection tools, election cybersecurity, regulatory action, and public education.
This report aims to raise awareness about the scams discussed above and outlines potential methods for identifying them. It is crucial for technology to keep pace with the rapid evolution of scams to effectively counteract them. To contribute to this effort, this report serves as a case study demonstrating the use of CloudSEK’s Deepfake Analyzer for scam detection and analysis.
Misinformation
Election Fraud
Modus Operandi:
- Initial Misinformation about Elections: The facebook ads show sensational or misleading claims about election processes or outcomes, aiming to foster distrust and intrigue among readers. The threat actors amplify the message across social media, emails, or conspiracy websites to maximize reach and attract susceptible audiences. Emotionally charged language is used to evoke fear, urgency, or anger, priming readers to search for further information or solutions.
- Redirect to fake domain: Once the user clicks on any such ad, it redirects them to a fake website ‘pro.insightandincome.com’ that contains a long video that promotes a book or resource that allegedly offers insider knowledge or strategies related to the elections. The tactic includes using clickbait-style headlines and emotional appeals to drive traffic, while the ultimate goal is likely to harvest user information or encourage financial transactions for the promoted material.
- Payment Gateway: Clicking the ‘Subscribe Now’ or purchase button leads users to a fraudulent domain ‘order.paradigm-press.info’ that is impersonating the official Paradigm Press website via its logo. The website then asks users to enter financial information and complete the purchase to get the book delivered to them.
Redirect chain:
- http://clicks.americanfreedomreport.org/aff_c?offer_id=980&aff_id=1028&url_id=834
- https://pro.insightandincome.com/p/awn_electionmeltdown49_1024/PAWN4A31/?cake_s1=11_170645966_c8ac1e1e-8d96-4cf5-96f3-e255d891b028&h=true
- https://order.paradigm-press.info/journey/awn_electionmeltdown49_1024/1?promocode=PAWN4A31&cake_s1=11_170629663_0f143a3f-929f-4629-b6b8-ab52a9b45ff...&pagenumber=2&organization-abbreviation=AF
Impact:
- The advertiser named ‘The Tech Prophet’ has spent $271,469 between 7 May 2018 - 1 Nov 2024 on these ads that have reached an audience of 4K-5K people per advertisement. The advertiser is running 100+ ads on the facebook platform as of writing this article.
- In total the advertiser has spent almost $6K-$7K (USD) on these ads that has reached a staggering 125K-150K users in the United States.
Source:
Health Science Institute
Modus Operandi:
- Initial Misinformation about Elections from Doctors: Some advertisements redirected users to a website on the domain ‘pro.joinhsi.com’. The website featured claims about benefits and unique solutions for health issues. The language used is persuasive, focusing on urgency and personal empowerment. The content often lacks scientific backing, raising concerns about misinformation and the potential exploitation of vulnerable individuals seeking health solutions.
- Payment Gateway: Once the users click on a button to get a free subscription, they are redirected to another domain ‘secure.hsionlineorders.net’. That accepts payments in the form of a subscription model. Many people have complained on websites such as ripoffreport.com that they made the payment and never received the book.
Redirect chain:
- http://clicks.click-cue.com/aff_c?offer_id=1045&aff_id=1034
- https://pro.joinhsi.com/p/HSIDOARFK0924A/PHSI4916/?ef_tx_id=7fe2a43be63646759239fd4fbc8312e5&ef_o_id=4842&aid=664&sid1=102ae568215266971073173eb2548d&h=true
- https://secure.hsionlineorders.net/journey/HSIDOARFK0924A/1?promocode=PHSI4916&ef_tx_id=7fe2a43be63646759239fd4fbc8312e5&ef_o_id=4842&aid=664&sid1=102ae568215266971073173eb2548d&h=true&pagenumber=2&organization-abbreviation=NMG
Impact:
Similar to the previous scam, the advertiser for such ads is also ‘The Tech Prophet’ and each ad has reached 2-3k users in the United states.
Sources:
- https://www.facebook.com/ads/library/?active_status=active&ad_type=political_and_issue_ads&country=US&media_type=all&page_ids[0]=185997467933016&q=election&search_type=keyword_unordered&sort_data[direction]=desc&sort_data[mode]=total_impressions&source=fb-logo
- https://www.ripoffreport.com/reports/health-science-institute/internet/health-science-institute-their-webs-site-showed-up-on-my-email-listen-to-our-report-order-1275031
Scams
Stimulus Scam
Modus Operandi:
- Misleading Videos: The scam begins with an AI-generated video that falsely claims the government is releasing a new stimulus package before elections, creating urgency and interest among viewers.
- Initial Redirection: Viewers are then redirected to the site ‘prizestash.com’, which serves as the main platform for harvesting personal information.
- Information Collection: Upon clicking the button, users are prompted to enter sensitive personal identifiable information (PII), including their zip code, name, email address, and phone number.
- Survey Engagement: After users submit this information and answer additional survey questions, they are redirected to other domains, such as p2a.co or blissxo.com. These sites further request more personal data or credit card information, leveraging the initial engagement to extract even more sensitive details.
Using our Deepfake analyser at https://community.cloudsek.com, we have verified that most of these videos are AI generated.
Redirect chain:
- https://track.mjpath.com/6706f148d6bccfb31ff5326d
- https://chance26.prizestash.com/a?vid=100&zDc=Desktop&zEx=&zVr=PT0016&c1=1267&c2=10269afc1efd51b0e6fefaf6cca80e&click_id=2998323987&utm_content=ps_viscard3_1000&utm_medium=&utm_source=462086&utm_term=1267&zRid=PT&zct=ps_viscard3_1000&zmd=&zsr=462086&ztm=1267
- https://monetize.zeeto.io/linkout/e0e652c2-dc3d-4552-b44f-66c6d5bddc72
- https://my.blissxo.com/f/125-instant-play/?utm_source=ZAN-1522&utm_medium=Linkout-inpath-CPA&utm_campaign=670951fe91440020b7b418e5&utm_content=BXO+Desktop&utm_term=71da47f2c6f745278bbc45c030ffc04b&clickid=1022c5c53cc1d6dda4152956cc3466&affid=1522&offer_id=21634&campaignid=670951fe91440020b7b418e5&adgroupid=21634&email=dssad%40sdsad.com&firstname=da&lastname=sdsa&zipcode=32322&city=Carrabelle&state=FL&address=dasda&phone=323-232-3232&dobmonth=02&dobday=12&dobyear=1995&gender=Female&bid_price=1.00
Impact:
The advertiser for such ads is ‘Liberty Giveaways’ that is running 290+ such fraudulent advertisements in the month of October with each advertisement reaching 3K-4K users in the United States.
Sources:
Crypto Scams
Creating Phony Tokens on Solana Network
Threat actors create fake Solana tokens and distribute them through airdrops and token offerings. They then solicit additional funds from victims under the pretense of marketing and promotion, ultimately absconding with the money.
Modus Operandi:
- Create a token on Solana Network with names referencing the US Elections and its candidates.
- Offer a Consumer Token Offering (CTO) to build hype and initiate trading of the phony token.
- Ask for more investment to help promote and legitimize the coin through marketing and the creation of a website.
- Threat Actors keep funds collected for themselves
Impact:
- Financial Loss for Victims: Investors lose money when they are deceived into funding fraudulent tokens.
- Market Volatility: The introduction of fake tokens can create instability in the market, affecting legitimate projects.
- Regulatory Scrutiny: Increased scams may lead to heightened regulatory oversight and scrutiny in the cryptocurrency space.
- Targeting Unsophisticated Investors: Cybercriminals often target inexperienced investors, exacerbating issues related to financial literacy in the crypto space.
- Difficulty in Recovery: Victims often find it challenging to recover lost funds, contributing to a sense of helplessness.
- Resource Diversion for Security: Increased scams necessitate more resources from exchanges and developers to enhance security measures and educate users.
Source:
The following telegram channels have been found promoting this type of scam:
- https://t.me/TrumpManiaSol (300+ members)
- https://t.me/KamaHarrisoll (100+ members)
- https://t.me/trumpXelonSOL (100+ members)
- https://t.me/presidentcryptotrump (200+ members)
Investment Pool Scams Using Fake Crypto Tokens and Deepfake Videos
Cybercriminals are creating fraudulent tokens and falsely associating them with presidential campaigns. They deceive investors into donating funds, promising to support political initiatives, but ultimately misappropriate the money.
Modus Operandi:
- To promote the investment in the tokens, threat actors are advertising using collected funds to aid presidential campaigns
- Threat Actors also create DeepFake videos of the presidential candidates to show their endorsement of different Crypto tokens to promote investment further
- Instead of donating the funds to the presidential candidates and their campaigns as promised, the threat actors keep the money for themselves
Impact:
- Financial Loss for Investors: Donors are misled into contributing funds, resulting in significant financial losses.
- Erosion of Trust: Incidents of fraud undermine public confidence in legitimate political fundraising and cryptocurrency initiatives.
- Stifling Political Campaigns: Genuine campaigns may struggle to attract donations if potential donors become wary of scams.
- Legal Repercussions: Campaigns and platforms may face legal challenges due to association with fraudulent activities, even if they are victims.
- Increased Regulation: Heightened awareness may lead to stricter regulations in both political fundraising and cryptocurrency markets.
- Damage to Campaign Reputation: Legitimate campaigns may suffer reputational harm as they are wrongly linked to fraudulent activities.
- Targeting Vulnerable Donors: Cybercriminals often exploit less informed or vulnerable individuals, exacerbating issues of financial literacy.
- Difficulty in Recovery: Recovering funds from fraudulent schemes can be complex and often unsuccessful, leaving victims without recourse.
Source:
The following telegram channels were found to be promoting these scams:
- https://t.me/FistTrumpPump (1400+ members)
- https://t.me/CTO_bookoftrump (600+ members)
- https://t.me/VTRUMPMEMECOIN (300+ members)
- https://t.me/kamalaharris_eth_cto (200+ members)
- https://t.me/kamlahorrishwillrise (100+members)
Attribution
For the Election Fraud Scam and HSI scam, the advertiser named ‘The Tech Prophet’ has listed its phone number as ‘+16193412211’ and email address ‘[email protected]’. The same phone number is also used by a facebook page called Market monitors. The page also has an email address present on it.
There are two domains on the page that are being handled by the advertiser:
- themarketmonitors.com: Features news articles and commentary on various political and economic topics.
- prohealthdigital.com: Claims to offer ‘high quality leads and sales for you.’
The advertiser for the stimulus scam named ‘Liberty Giveaway Found’ has listed the following details:
Mitigations
Technological Measures
- AI-Powered Detection Tools:some text
- Utilize AI-powered tools like CloudSEK's Community Deepfake Analyzer to detect and identify deepfake content.
- Implement advanced machine learning algorithms to identify and flag misinformation and disinformation campaigns.
- Robust Cybersecurity Infrastructure:some text
- Strengthen the security of election infrastructure, including voting machines, voter registration databases, and election management systems.
- Implement strong cybersecurity measures to protect against cyberattacks, such as phishing, malware, and ransomware.
- Digital Forensics:some text
- Develop robust digital forensics capabilities to investigate and trace the origin of malicious content and cyberattacks.
Legal and Regulatory Measures
- Enforcing Existing Laws: Enforce existing laws related to election interference, campaign finance, and fraud.
- Strengthening Regulations: Consider enacting new legislation to address the evolving nature of cyber threats, including those related to deepfakes and cryptocurrency scams.
- International Cooperation: Collaborate with international partners to share information and coordinate efforts to combat cyber threats.
Social and Educational Measures
- Media Literacy: Promote media literacy among the public to help them identify and critically evaluate misinformation and disinformation.
- Social Media Literacy: Educate users about the risks of social media, including the spread of fake news and misinformation.
- Fact-Checking Organizations: Support fact-checking organizations to debunk false information and promote accurate news.
- Public Awareness Campaigns: Launch public awareness campaigns to inform the public about the dangers of cyber threats and how to protect themselves.