
Fake Advisors, ClickFix, and Chrome Sync Spying
This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…
U.S. prosecutors said Derrick Van Yeboah ran long-running romance scams by posing as fake romantic partners online and persuading mostly older, vulnerable victims to send money. In one example, he claimed he needed funds for his mother’s funeral and to recover “imaginary gold and diamonds” from storage in Italy, leading a victim to send $123,000.
Prosecutors described a long-running scheme in which a Ghanaian national impersonated romantic partners online and interacted with victims for close to nine years, from February 2015 to October 2024. Rather than relying on a single fast-moving lure, the operation built relationships over time, establishing trust before introducing financial requests. Once that trust was in place, the scammer introduced fabricated emergencies designed to feel urgent and personal, such as needing a loan for a mother's funeral expenses or fees to recover gold and diamonds held in overseas storage. In one documented case, this pretext led a victim to send $123,000.
The scheme worked because it exploited an emotional relationship rather than a technical vulnerability. Victims believed they were helping someone they cared about, not responding to a stranger's request. The overseas valuables story added a sense of legitimacy and complexity that discouraged questioning, while the funeral request appealed directly to empathy. Some victims went further than sending money themselves: they were persuaded to create companies that were then used to unwittingly launder funds taken from other victims, turning trusting individuals into unintentional participants in the fraud.
Defenders and awareness programs should highlight these patterns:
Organizations can reduce harm from this pattern by training employees, especially those who may be more socially isolated or active on dating and social platforms, to recognize that any online relationship requesting money is a serious warning sign. People should be encouraged to pause and verify through trusted, independent channels before sending funds or agreeing to financial favors for someone they have not met in person. Awareness efforts should also make clear that creating a company or moving money for an online contact can turn a victim into an unwitting money mule. Finally, because romance scams can cause both financial and emotional harm, including loss of retirement savings and distress upon discovering the relationship was fraudulent, support resources and early reporting channels matter as much as prevention messaging.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
He posed as a romantic partner online for years, then fabricated emergencies like funeral expenses and fees to recover valuables held overseas to pressure victims into sending funds.
Some victims were also manipulated into creating companies that were then used to unwittingly launder funds from other victims.
Prosecutors said the scammer impersonated romantic partners and interacted with victims online from February 2015 to October 2024, about nine years.
Urgent money requests, stories involving overseas storage fees for valuables like gold or diamonds, and pressure to keep the relationship or request private and time-sensitive are common warning signs.
Someone just got 85 months in prison for stealing over $10 million by pretending to be people’s online boyfriend or girlfriend. For nine years he posed as romantic partners online, then dropped messages like, “I hate to ask, but I need a loan for my mother’s funeral… and to get gold and diamonds out of storage in Italy.” One victim sent $123,000. Here’s the twist: some victims were even convinced to create companies to 'help move money safely', they were actually laundering cash for other victims without realizing it. Aha moment: the second an online relationship asks for money or to move money, treat it as a scam until proven otherwise, pause, don’t send, and report it to Security or HR.

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked…

Attackers compromised hundreds of legitimate websites and injected code that sent visitors to a fake Cloudflare page. The fake page used a “ClickFix” trick to…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Researchers reported a months-long campaign where attackers used Microsoft Teams chats/calls while pretending to be IT/help desk support. Victims were talked…

South Korean agencies and AhnLab warn that tools tied to North Korea’s Lazarus Group appear to be shared with the Gunra ransomware operation targeting South…