This cluster centers on 2874 connected domains tagged as QuasarRAT, StealitStealer, pw-k53mv9bc. 652 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus.
The connected infrastructure includes 1375 phone numbers (2157987305, 2025069230, 2028641298) with 14635 FTC complaints; 160 companies (JPMORGAN CHASE & CO., Advanced Resolution Services Inc., EVERBANK, NATIONAL ASSOCIATION) with 8680419 CFPB complaints; 299 email addresses (abuse@fb.com, xxxxxxxxxxxxxxxxxxxxxxxx@vmh5.grupoaldama.com.mx, someone@paypal.com).
Across all linked entities, consumers have filed 8697936 complaints with federal agencies.
Geographically, consumer complaints associated with this campaign are concentrated in West Palm Beach, Florida, Las Vegas, Nevada, Orlando, Florida, San Diego, California, Chicago, Illinois. This regional pattern may indicate targeted operations or reflect where the scam has been most actively reported.
If you receive a call or text from any of these numbers, do not engage — hang up immediately and do not call back. Never provide personal information or make payments to unknown callers. Do not click links to any of the flagged domains. If you have visited one, check your accounts for unauthorized activity and consider changing your passwords. If you were contacted by any of these companies, verify their legitimacy by looking up their official contact information independently — do not use phone numbers or links provided in the suspicious communication. Do not reply to suspicious emails or click any links or attachments they contain. Check the sender's domain carefully for misspellings or unusual variations. You can report suspicious contacts to the FTC at reportfraud.ftc.gov or to the FCC at consumercomplaints.fcc.gov.
This campaign was identified through automated analysis of FTC/FCC complaint databases, threat intelligence feeds, CFPB consumer complaints, email threat intelligence and entity relationship mapping.