{"investigation":{"slug":"fake-crypto-aml-checker-infrastructure","entity_name":"Fake Crypto AML Checker Infrastructure","trust_score":0,"severity_base":null,"score_modifier":-13,"confidence":0.88,"status":"published","content_type":"investigation","summary":"A coordinated network of fraudulent websites impersonating legitimate anti-money laundering (AML) compliance tools — most prominently AMLBot — was publicly documented by Malwarebytes on August 19, 2026. The sites simulate wallet-risk screening workflows to social-engineer users into connecting wallets and signing drainer transactions, in some cases also charging small upfront 'verification fees.' The campaign is notable for targeting security-conscious users who are actively trying to verify their own wallet safety, and for the systematic reuse of a shared malicious site template rebranded under multiple names and logos.","sections":[{"content":"Malwarebytes threat researcher Stefan Dasic published a report on August 19, 2026 documenting an active wave of fraudulent websites designed to impersonate legitimate crypto AML (anti-money laundering) screening services. The campaign was independently corroborated by Decrypt, Security Boulevard, Cryptopolitan, and Coin-Turk on the same date. Fake sites replicate the branding, layout, and language of established services — most commonly AMLBot (amlbot.com) — or operate under generic names such as 'AML Check.' Malwarebytes observed that the same core malicious site template has been 'systematically reused and rebranded' across numerous domains, indicating a coordinated operation rather than isolated incidents. The attack surface is atypical: by masquerading as a trust-and-safety tool, the operators specifically prey on users who are already security-aware and motivated to verify their wallet risk status.","heading":"Campaign Overview","sources":[{"url":"https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet","name":"Malwarebytes: Scammers are using fake crypto AML checkers to drain your wallet","type":"research","credibility":1},{"url":"https://decrypt.co/376029/fake-crypto-aml-drain-users-wallets","name":"Decrypt: Fake Crypto AML Checkers Are Trying to Drain Users' Wallets","type":"news_article","credibility":2},{"url":"https://www.cryptopolitan.com/fake-crypto-aml-checkers-drain-wallets/","name":"Cryptopolitan: Fake crypto AML checkers push users to approve wallet-draining transactions","type":"news_article","credibility":2},{"url":"https://en.coin-turk.com/malwarebytes-warns-of-fake-aml-crypto-sites-targeting-wallet-permissions/","name":"Coin-Turk: Malwarebytes warns of fake AML crypto sites targeting wallet permissions","type":"news_article","credibility":2}],"severity":"critical"},{"content":"The fake sites follow a multi-stage social engineering sequence. First, users are prompted to enter or connect a wallet for what appears to be a routine AML compliance scan. The site displays fabricated progress indicators — messages such as 'Checking wallet history' and 'Verifying compliance' — before returning a fraudulent result, typically 'Clean, Low Risk,' sometimes accompanied by an offer to download a formal-looking report. In some variants documented by Malwarebytes and Cryptopolitan, an error message appears partway through requesting a small upfront fee in cryptocurrency to complete the scan; paying this fee creates a false impression of legitimacy while also delivering a minor immediate gain to the operator. The critical step occurs when the user connects their Web3 wallet: according to PCrisk's technical analysis, the wallet connection action itself triggers the signing of a malicious smart contract, which authorizes automated fund transfers. Malwarebytes notes that connecting a wallet reveals the wallet's full asset holdings, allowing operators to tailor subsequent fraudulent transactions to target the highest-value assets first. Crypto transactions are irreversible once confirmed on-chain, and the pseudonymous nature of the drainer wallets makes asset recovery effectively impossible.","heading":"Drainer Mechanics","sources":[{"url":"https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet","name":"Malwarebytes: Scammers are using fake crypto AML checkers to drain your wallet","type":"research","credibility":1},{"url":"https://www.cryptopolitan.com/fake-crypto-aml-checkers-drain-wallets/","name":"Cryptopolitan: Fake crypto AML checkers push users to approve wallet-draining transactions","type":"news_article","credibility":2},{"url":"https://www.pcrisk.com/removal-guides/32520-fake-amlbot-website-scam","name":"PCrisk: Fake AMLBot Website Scam — Removal and recovery steps","type":"research","credibility":2}],"severity":"critical"},{"content":"PCrisk's removal guides, updated through mid-2026, document two overlapping sets of fraudulent domains attributed to this campaign family. The first set includes: amlbot.seize[.]report (serving IP 104.26.9.244, flagged as malicious by Certego, CRDF, and Seclookup; VirusTotal hash bb78178c3f52e0c167e78f47d63259518cc490ca1aafb283fd2f6d608d5a9168), amlbot[.]sale, av3d[.]fr, amlbotchecks[.]com, aml-safety[.]app, amlrobotsaveru[.]com, amlreport-app[.]com, and amlpremium[.]top. A second set includes: amlbotchecking[.]com, aml-bot.co[.]com, aml-safety[.]one, amlnix[.]com, and amlbot[.]club (serving IP 104.21.15.211). Malwarebytes did not publish specific domain lists in its August 2026 report, instead characterizing the operation as a template-based kit systematically rebranded across an unspecified number of additional domains. Distribution vectors include compromised third-party websites, social media spam, rogue pop-up advertisements, and potentially unwanted applications. The breadth of domains and the shared template infrastructure suggest the drainer kit may be commercially distributed or available on cybercrime forums, consistent with a separate Cryptopolitan-cited report of a $500 turnkey kit creating fake token presale phishing sites.","heading":"Known Fake Domains and Technical Indicators","sources":[{"url":"https://www.pcrisk.com/removal-guides/32520-fake-amlbot-website-scam","name":"PCrisk: Fake AMLBot Website Scam — Removal and recovery steps","type":"research","credibility":2},{"url":"https://www.pcrisk.com/removal-guides/33236-amlbot-crypto-checking-scam","name":"PCrisk: AMLBot Crypto Checking Scam — Removal and recovery steps","type":"research","credibility":2},{"url":"https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet","name":"Malwarebytes: Scammers are using fake crypto AML checkers to drain your wallet","type":"research","credibility":1}],"severity":"critical"},{"content":"AMLBot (amlbot.com) is a legitimate commercial AML compliance tool that analyzes wallet transaction history against sanctions lists, hack databases, and other risk indicators using only a submitted public wallet address — it does not require wallet connection, approval of permissions, or transaction signatures. AMLBot published an official warning on its blog (initially April 2025, updated through 2025) alerting users to the impersonation campaign. The company states it will never ask users to connect a Web3 wallet, approve token permissions, or provide a recovery phrase or private key. AMLBot identifies the impersonation vectors as email, Telegram, and fake websites, with fraudulent entities using names including 'AMLBot Recovery' and 'AMLBot Investigation Team.' AVOID.NET notes that AMLBot is a victim of brand impersonation in this campaign, not a perpetrator. Users encountering any AMLBot-branded service that requests wallet connection should treat it as fraudulent and verify through official channels at amlbot.com directly.","heading":"Impersonation of AMLBot — Legitimate Service","sources":[{"url":"https://blog.amlbot.com/dont-get-tricked-by-fake-amlbot-platforms-protect-your-crypto-from-scammers/","name":"AMLBot Blog: Don't Get Tricked by Fake AMLBot Platforms","type":"official","credibility":1},{"url":"https://decrypt.co/376029/fake-crypto-aml-drain-users-wallets","name":"Decrypt: Fake Crypto AML Checkers Are Trying to Drain Users' Wallets","type":"news_article","credibility":2}],"severity":"high"},{"content":"This campaign is structurally distinct from conventional crypto phishing in that it selectively targets users who are already security-conscious. Retail traders, NFT collectors, and DeFi participants who want to verify that a counterparty wallet is 'clean' before transacting are the primary intended victims. By adopting the facade of a compliance and risk tool, the operators exploit the defensive intent of the target rather than relying on greed or urgency. Crypto Economy and Cryptopolitan reporting notes that the targeted pool includes users verifying seller provenance, confirming a wallet's history before a trade, or otherwise taking proactive security steps — behaviors that normally reduce risk but in this context serve as the attack vector. This inversion of security intent represents a novel social engineering approach that may be particularly effective against technically intermediate users who understand the concept of AML screening but have not encountered this class of scam before.","heading":"Target Demographics and Attack Novelty","sources":[{"url":"https://crypto-economy.com/scammers-pose-as-crypto-aml-tools-to-trick-users-into-approving-risky-transactions/","name":"Crypto Economy: Scammers Pose as Crypto AML Tools to Trick Users Into Approving Risky Transactions","type":"news_article","credibility":2},{"url":"https://www.cryptopolitan.com/fake-crypto-aml-checkers-drain-wallets/","name":"Cryptopolitan: Fake crypto AML checkers push users to approve wallet-draining transactions","type":"news_article","credibility":2}],"severity":"high"},{"content":"Malwarebytes and all corroborating sources agree on a single definitive indicator: a legitimate AML screening service requires only a wallet's public address. Any service that requests wallet connection, prompts approval of token permissions, asks a user to sign a transaction, or requests a private key or recovery phrase is not a legitimate AML tool. Stefan Dasic of Malwarebytes stated: 'If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign.' AMLBot's official guidance confirms the same standard for its own legitimate service. Additional red flags include: upfront fees payable in cryptocurrency before results are displayed; results that appear regardless of actual wallet history (i.e., always returning 'Clean'); domains that closely approximate but do not exactly match known legitimate services; and sites encountered via social media advertisements, pop-up windows, or unsolicited messages rather than direct navigation.","heading":"Definitive Red Flags","sources":[{"url":"https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet","name":"Malwarebytes: Scammers are using fake crypto AML checkers to drain your wallet","type":"research","credibility":1},{"url":"https://blog.amlbot.com/dont-get-tricked-by-fake-amlbot-platforms-protect-your-crypto-from-scammers/","name":"AMLBot Blog: Don't Get Tricked by Fake AMLBot Platforms","type":"official","credibility":1},{"url":"https://decrypt.co/376029/fake-crypto-aml-drain-users-wallets","name":"Decrypt: Fake Crypto AML Checkers Are Trying to Drain Users' Wallets","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Malwarebytes published the following guidance for users who may have interacted with fake AML checker sites. Users who only entered a public wallet address face no immediate risk, as this reveals no non-public information. Users who connected their wallet should disconnect the site immediately and audit active token approvals using a tool such as Revoke.cash or a wallet's built-in permission manager, revoking any unfamiliar approvals. Users who approved token permissions should act immediately to revoke those permissions, as pending drainer transactions may execute at any time. Users who signed any unrecognized transaction should assume the wallet is compromised and move all assets to a freshly generated wallet with a new seed phrase. Users who entered a recovery phrase or private key should treat the wallet as fully compromised and migrate all assets immediately. Crypto transactions that have already executed cannot be reversed.","heading":"Remediation Guidance","sources":[{"url":"https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet","name":"Malwarebytes: Scammers are using fake crypto AML checkers to drain your wallet","type":"research","credibility":1},{"url":"https://www.pcrisk.com/removal-guides/32520-fake-amlbot-website-scam","name":"PCrisk: Fake AMLBot Website Scam — Removal and recovery steps","type":"research","credibility":2}],"severity":"medium"},{"content":"The fake AML checker campaign exists within a wider ecosystem of template-based crypto phishing infrastructure. Cryptopolitan's August 2026 coverage references a $500 commercially available kit that generates fake token presale sites. Separately, fake Jupiter airdrop tokens on Solana have been observed flooding wallets with drainer redirect links. CoinDCX reported more than 1,200 fake websites impersonating its exchange platform between April 2024 and January 2026. PCrisk also documented a parallel fake Coldcard hardware wallet site in the same campaign period. The US Federal Trade Commission (FTC), cited by PCrisk, reported that since 2021 more than 46,000 people reported losing over $1 billion in cryptocurrency to scams broadly — approximately one in four dollars of all reported fraud losses. The fake AML checker infrastructure appears to represent a specialist vertical within this ecosystem, monetizing the demand for compliance verification that has grown as regulatory awareness in the crypto space has increased.","heading":"Broader Context: Phishing Kit Ecosystem","sources":[{"url":"https://www.cryptopolitan.com/fake-crypto-aml-checkers-drain-wallets/","name":"Cryptopolitan: Fake crypto AML checkers push users to approve wallet-draining transactions","type":"news_article","credibility":2},{"url":"https://www.pcrisk.com/removal-guides/32520-fake-amlbot-website-scam","name":"PCrisk: Fake AMLBot Website Scam — Removal and recovery steps","type":"research","credibility":2},{"url":"https://crypto-economy.com/scammers-pose-as-crypto-aml-tools-to-trick-users-into-approving-risky-transactions/","name":"Crypto Economy: Scammers Pose as Crypto AML Tools to Trick Users Into Approving Risky Transactions","type":"news_article","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2025-04-16","event":"AMLBot publishes initial warning on its official blog about fraudulent sites and Telegram accounts impersonating its brand, requesting wallet access and upfront payments.","source":"AMLBot Blog","source_url":"https://blog.amlbot.com/dont-get-tricked-by-fake-amlbot-platforms-protect-your-crypto-from-scammers/"},{"date":"2025-03-26","event":"PCrisk publishes removal guide for fake AMLBot website scam, identifying domains including amlbot.seize[.]report, amlbot[.]sale, amlbotchecks[.]com, and aml-safety[.]app, with IP 104.26.9.244.","source":"PCrisk","source_url":"https://www.pcrisk.com/removal-guides/32520-fake-amlbot-website-scam"},{"date":"2025-06-26","event":"PCrisk publishes second removal guide documenting a distinct cluster of fake AMLBot domains including amlbotchecking[.]com, aml-bot.co[.]com, aml-safety[.]one, amlnix[.]com, and amlbot[.]club, with IP 104.21.15.211.","source":"PCrisk","source_url":"https://www.pcrisk.com/removal-guides/33236-amlbot-crypto-checking-scam"},{"date":"2025-11-10","event":"AMLBot updates its official warning blog post, indicating the impersonation campaign has persisted for at least seven months.","source":"AMLBot Blog","source_url":"https://blog.amlbot.com/dont-get-tricked-by-fake-amlbot-platforms-protect-your-crypto-from-scammers/"},{"date":"2026-06-02","event":"PCrisk updates its second removal guide, confirming the second domain cluster remains active.","source":"PCrisk","source_url":"https://www.pcrisk.com/removal-guides/33236-amlbot-crypto-checking-scam"},{"date":"2026-08-19","event":"Malwarebytes threat researcher Stefan Dasic publishes a report on the active fake AML checker campaign, documenting AMLBot impersonation, 'AML Check' generic branding, fake progress indicators, fabricated scan results, small upfront verification fees, and wallet drainer mechanics. Report corroborated same day by Decrypt, Security Boulevard, Cryptopolitan, and Coin-Turk.","source":"Malwarebytes","source_url":"https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet"}],"sources_used":[{"url":"https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet","name":"Malwarebytes: Scammers are using fake crypto AML checkers to drain your wallet","type":"research","archive_url":"http://web.archive.org/web/20260821030159/https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet","credibility":1,"archive_timestamp":"2026-08-21T03:01:59+00:00"},{"url":"https://decrypt.co/376029/fake-crypto-aml-drain-users-wallets","name":"Decrypt: Fake Crypto AML Checkers Are Trying to Drain Users' Wallets","type":"news_article","archive_url":"http://web.archive.org/web/20260821084108/https://decrypt.co/376029/fake-crypto-aml-drain-users-wallets","credibility":2,"archive_timestamp":"2026-08-21T08:41:08+00:00"},{"url":"https://securityboulevard.com/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet/","name":"Security Boulevard: Scammers are using fake crypto AML checkers to drain your wallet","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.cryptopolitan.com/fake-crypto-aml-checkers-drain-wallets/","name":"Cryptopolitan: Fake crypto AML checkers push users to approve wallet-draining transactions","type":"news_article","archive_url":"https://web.archive.org/web/20260825025836/https://www.cryptopolitan.com/fake-crypto-aml-checkers-drain-wallets/","credibility":2,"archive_timestamp":"2026-08-25T02:58:36+00:00"},{"url":"https://en.coin-turk.com/malwarebytes-warns-of-fake-aml-crypto-sites-targeting-wallet-permissions/","name":"Coin-Turk: Malwarebytes warns of fake AML crypto sites targeting wallet permissions","type":"news_article","archive_url":"https://web.archive.org/web/20260825003938/https://en.coin-turk.com/malwarebytes-warns-of-fake-aml-crypto-sites-targeting-wallet-permissions/","credibility":2,"archive_timestamp":"2026-08-25T00:39:38+00:00"},{"url":"https://blog.amlbot.com/dont-get-tricked-by-fake-amlbot-platforms-protect-your-crypto-from-scammers/","name":"AMLBot Blog: Don't Get Tricked by Fake AMLBot Platforms","type":"official","archive_url":"http://web.archive.org/web/20260512184453/https://blog.amlbot.com/dont-get-tricked-by-fake-amlbot-platforms-protect-your-crypto-from-scammers/","credibility":1,"archive_timestamp":"2026-05-12T18:44:53+00:00"},{"url":"https://www.pcrisk.com/removal-guides/32520-fake-amlbot-website-scam","name":"PCrisk: Fake AMLBot Website Scam — Removal and recovery steps","type":"research","archive_url":"http://web.archive.org/web/20260518124532/https://www.pcrisk.com/removal-guides/32520-fake-amlbot-website-scam","credibility":2,"archive_timestamp":"2026-05-18T12:45:32+00:00"},{"url":"https://www.pcrisk.com/removal-guides/33236-amlbot-crypto-checking-scam","name":"PCrisk: AMLBot Crypto Checking Scam — Removal and recovery steps","type":"research","archive_url":"http://web.archive.org/web/20260208051009/https://www.pcrisk.com/removal-guides/33236-amlbot-crypto-checking-scam","credibility":2,"archive_timestamp":"2026-02-08T05:10:09+00:00"},{"url":"https://crypto-economy.com/scammers-pose-as-crypto-aml-tools-to-trick-users-into-approving-risky-transactions/","name":"Crypto Economy: Scammers Pose as Crypto AML Tools to Trick Users Into Approving Risky Transactions","type":"news_article","archive_url":"http://web.archive.org/web/20260825003546/https://crypto-economy.com/scammers-pose-as-crypto-aml-tools-to-trick-users-into-approving-risky-transactions/","credibility":2,"archive_timestamp":"2026-08-25T00:35:46+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-08-24T23:04:04.681911+00:00","updated_at":"2026-08-25T03:01:56.140957+00:00"}}