Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Fake crypto scams try to piggyback off SpaceX IPO

hy0zu0fuf7rc2ou5aje.live

TLP:CLEAR
Active

Domain

Description

Scammers are exploiting public interest in the SpaceX IPO through fraudulent investment portals impersonating SpaceX, Elon Musk, and major financial brands including Fidelity and Robinhood. The campaign uses themed domains to lure victims into fake onboarding processes that mimic legitimate investment procedures, including W-8BEN tax forms for non-U.S. investors. Victims are asked to select investment tiers and ultimately directed to deposit funds via cryptocurrency wallets for Bitcoin, Ethereum, and USDT. The operation mirrors techniques used by threat actor TA2730 but focuses on direct cryptocurrency theft rather than credential harvesting. One Bitcoin wallet associated with the campaign received approximately $8,700. The infrastructure includes randomized domains and SpaceX-themed domains designed to appear legitimate during the investment process.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Fake crypto scams try to piggyback off SpaceX IPO
Pattern Type
STIX
Confidence
75%
Valid From
Jul 15, 2026 22:00
Total Sightings
0
Added
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of hy0zu0fuf7rc2ou5aje.live

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.