The group establishes credibility with the targeted CEOs through various common phishing tactics such as claiming to be connected to recognized investors in the target’s industry; maintaining a professional and credible-looking website; contacting targets directly via LinkedIn and flying targets overseas to meet the purported representatives in luxury hotels and restaurants.
The message to these CEOs, and ultimately the basis of the scheme, is that before they can receive a multimillion-dollar investment, they must set aside a reserve fund, typically about 10% of the total investment, in an account that can be monitored by the investor over time.
While this may appear to be a straightforward request, a significant red flag is that the investor requires the reserve fund to consist of digital assets held in a noncustodial blockchain wallet rather than fiat funds in a bank account. This is a highly suspicious request and may be a significant cause for concern.
The theft itself works very much like a tech support scam. The would-be investors will ask the target to click on a link or QR code so they can assist with setting up the reserve funds on-chain. Clicking on anything sent may result in a malicious payload being placed onto the target’s device. That malware will request approval of something seemingly unrelated or harmless but actually will drain the target’s crypto address of all its funds.



