Authors: Vojtěch Šimeček, Tadeáš Hájek, Whalebone Threat Intelligence Analysts
Using online advertising for malicious purposes is almost as old as the internet itself. A single misplaced click can redirect users to a fake software download site, a fraudulent login page, or a website impersonating a trusted newspaper, where a convincing news story quietly promotes a fraudulent investment platform.
In July 2026, Whalebone Threat Intelligence uncovered a network of malicious websites impersonating well-known news outlets around the world. Although the names, faces, and headlines changed from country to country, each site was built for the same purpose: to gain the reader’s trust and steer them towards a fake investment platform.
The threat itself is not new and has resurfaced regularly in recent years. However, the scale and infrastructure of this campaign exceeded previously observed waves.
The language was convincing, the lookalike news sites were reproduced with considerable accuracy, and behind the pages was a professionally managed advertising and lead-generation system that measured visitor behavior, tracked conversions, and continuously replaced domains as they were detected.
During our investigation, we observed more than 400 domains targeting internet users in Australia, the Czech Republic, the United Kingdom, Japan, and other countries.
The Australian article we investigated was designed to resemble an ABC News story and centered on Professor Richard Scolyer, the prominent Australian medical researcher and joint 2024 Australian of the Year, who died on 7 June 2026.
Rather than beginning with an obvious financial promise, the article opened as a deeply personal story about his supposed will, his scientific legacy, and the future of his family. It claimed that, alongside his property, research archives, awards, and personal belongings, Scolyer had left his wife access to an investment account containing 600,000 AUD (~365,000 EUR).
According to the fabricated story, he had built the account using an artificial intelligence-powered trading platform called Zephgain. The implied message was clear: if one of Australia’s most trusted scientists had tested the platform and believed in it, ordinary readers could trust it too.
A fabricated editor’s note claimed that the ABC News editorial team had independently investigated Zephgain and confirmed its legitimacy. To create urgency, readers were then told that more than 12,000 Australians had already registered and that access would remain open for only another 24 hours.
The campaign changed its appearance for each country, but its underlying method remained the same.
Each site imitated a familiar local news outlet, reproducing its layout, branding, and editorial style. The attackers then placed recognizable public figures into an emotional or controversial story designed to attract attention and build trust.
The reader was introduced to a supposedly exclusive investment platform, encouraged to submit a phone number, and later contacted by a representative who requested an initial deposit.
The Czech version impersonated Seznam Zprávy and used a fabricated confrontation on a popular Czech late-night program. The story featured a well-known Czech mathematician, entrepreneur, and investor, challenging a senior banking executive before introducing the fraudulent investment platform.
The British version copied the appearance of the BBC. Its story claimed that an investigation had exposed financial technology allegedly kept by banks for wealthy clients, presenting the fake platform as a secret opportunity now available to ordinary people.
The Japanese version placed a journalist in a supposed confrontation with the governor of the Bank of Japan, using the dispute to suggest that important financial information had been hidden from the public.
The campaign operated more like a performance-marketing pipeline than a standalone scam page.
Captured URLs contained Meta campaign, ad-set, and creative identifiers, showing that victims were reached through paid social advertisements. The fake articles were also hidden behind campaign-specific links. Visiting the domain directly often returned an empty page, while users arriving with a valid campaign key saw the full content.
Each visitor received an individual tracking identifier. The operators could follow them from the fake news article to the investment platform and registration form.
The page also measured scroll depth, reading time, tab changes, and the point at which the visitor left.
The “investment platform” registration form generated a device identifier and submitted it together with the lead.
Hidden fields also recorded how long the victim spent reading the article and completing the form. This allowed the operators to evaluate lead quality and potentially recognize returning visitors, automated scanners, or researchers.
Landing-page paths contained country codes, names of the public figures used in the story, and campaign variant numbers.
The same kit also included localization material for roughly 25 countries. Operators could therefore reuse the same infrastructure while changing the newspaper, language, currency, and local personalities.
The domains were deliberately short-lived and easy to replace. Most used random, semi-pronounceable names on inexpensive top-level domains such as .info, .top, .pro, .xyz, and .sbs, and had been registered within the previous four weeks.
The majority of the observed domains were hidden behind Cloudflare’s proxy service, likely to conceal the origin server and make the infrastructure more difficult to trace or disrupt.
The domains operated as interchangeable gateways to the same underlying infrastructure. When a campaign-specific URL path was requested across a set of ten domains, each domain served the same scam article. During July 2026, we identified more than 400 domains connected to this infrastructure.
Whalebone Threat Intelligence will continue to track these campaigns and block their domains at the DNS level, so our users can follow the news without following the scammers.