← AVOID.NET
Entity Graph
Browse extracted entities, relationships, and potential duplicates.
Total entities
22,563
Relationships
17,963
Potential duplicates
0
Filter by kind
Entities
↯23a3c8ef
SEC files civil fraud complaint against MCC International Corp., Emerson Sousa Pires, Luiz Carlos Capuci Jr., CPTLCoin Corp., and Bitchain Exchanges.(2022-04-22:emerson-sousa-pires)event
↯0559aa38
U.S. District Court for the Southern District of Florida issues a temporary restraining order and asset freeze against MCC International Corp., Capuci, and Pires following SEC complaint.(2022-04-21:emerson-sousa-pires)event
↯e4e705ef
EmpiresX stops honoring investor withdrawal requests.(2021-11-01:emerson-sousa-pires)event
↯8bbcfbc2
Pires and Goncalves launch EmpiresX (Empires Consulting Corp.) in South Florida, soliciting investors for an alleged cryptocurrency trading platform using a purported algorithmic 'bot'.(2020-09-01:emerson-sousa-pires)event
↯97c33b37
MCC International Corp. (Mining Capital Coin) allegedly begins selling fraudulent mining packages to investors, promising 1% daily returns. Pires and Capuci are co-founders.(2018-01-01:emerson-sousa-pires)event
↯31973ca5
Judge K. Michael Moore (S.D. Fla.) enters a $46 million default judgment against Capuci, Pires, MCC International, CPTLCoin Corp., and Bitchain Exchanges, comprising ~$28.5M disgorgement, ~$7.8M prejudgment interest, and civil monetary penalties.(2025-08-26:luiz-carlos-capuci-jr)event
↯b0ea1f86
U.S. magistrate judge recommends approximately $28 million in disgorgement against Capuci, Pires, and related entities in the SEC civil case.(2025-02-01:luiz-carlos-capuci-jr)event
↯e09a6d22
Criminal trial against Capuci begins in Brazil.(2024-08-21:luiz-carlos-capuci-jr)event
↯0795b86c
U.S. law firm Wellman & Warren LLP withdraws from representing Capuci, citing inability to pay; local counsel Gregg S. Lerman follows on August 22, 2024.(2024-08-02:luiz-carlos-capuci-jr)event
↯455a47db
Brazilian Federal Police launch Operation Yang; Capuci and Pires are arrested. Authorities freeze up to R$300 million (~$55M USD) in bank accounts and block 52 properties across Brazil.(2023-09-13:luiz-carlos-capuci-jr)event
↯5208fdef
U.S. court lifts the stay on the SEC civil case.(2023-06-10:luiz-carlos-capuci-jr)event
↯0797dd7b
Capuci's appeal of the SEC preliminary injunction is denied.(2023-05-31:luiz-carlos-capuci-jr)event
↯2db4962a
U.S. court grants SEC permission to serve Capuci via email through his U.S.-based attorneys after international service delays.(2023-03-08:luiz-carlos-capuci-jr)event
↯f94262c1
Brazilian Federal Police open a criminal investigation based on intelligence provided by U.S. Homeland Security Investigations (HSI).(2022-08-01:luiz-carlos-capuci-jr)event
↯932389dc
DOJ unseals indictment against Capuci (Case No. 22-20173-CR-Altonaga, S.D. Fla.) charging conspiracy to commit wire fraud, securities fraud, and international money laundering; maximum exposure of 45 years.(2022-05-05:luiz-carlos-capuci-jr)event
↯61e14b88
U.S. District Court for the Southern District of Florida issues a temporary restraining order and asset freeze against Capuci, Pires, MCC International, CPTLCoin Corp., and Bitchain Exchanges.(2022-04-21:luiz-carlos-capuci-jr)event
↯6e7cff3d
MCC International Corp. (Mining Capital Coin) begins selling mining packages to investors, promising 1% daily returns paid weekly for up to 52 weeks.(2018-01-01:luiz-carlos-capuci-jr)event
↯ef8d11f2
U.S. District Court enters a combined $46 million default judgment against MCC International Corp., CPTLCoin Corp., Bitchain Exchanges, Capuci, and Pires, comprising approximately $28.5 million in disgorgement and $7.8 million in prejudgment interest.(2025-08-26:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
↯82be6b15
Brazil's Federal Police launch Operation Yang, executing 25 search and seizure warrants across 8 states; Emerson Pires is reported arrested in Florianopolis; R$300 million in bank accounts frozen and 52 properties blocked.(2023-09-13:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
↯0c7e47f2
Brazilian authorities open an independent criminal investigation into MCC founders for alleged money laundering of up to R$300 million.(2022-08-01:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
↯3b602ad0
DOJ unseals criminal indictment against Luiz Carlos Capuci Jr. for conspiracy to commit wire fraud, securities fraud, and international money laundering in connection with the alleged $62 million scheme.(2022-05-08:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
↯57734f28
SEC publicly announces fraud charges against MCC International Corp., CPTLCoin Corp., Bitchain Exchanges, Luiz Carlos Capuci Jr., and Emerson Sousa Pires.(2022-05-06:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
↯f31fedae
U.S. District Court for the Southern District of Florida issues a temporary restraining order against all defendants and freezes their assets at the SEC's request.(2022-04-21:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
↯d6285c62
MCC International Corp. (Mining Capital Coin) begins selling fraudulent mining packages to investors, promising 1% daily returns paid weekly.(2018-01-01:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
△c4aaab78
MCC International Corp / CPTLCoin Corp / Bitchain Exchangesexchange
↯d13d97df
The Hacker News reports over 250 ClickFix domains using browser fingerprinting to serve platform-specific macOS malware lures, indicating campaign infrastructure has scaled to hundreds of distinct lure domains.(2026-08-08:clickfix-bnb-chain-etherhiding-malware-campaign)event
↯21892432
Huntress researchers separately document a Go-based macOS infostealer delivered via ClickFix attacks, capable of partially redirecting cryptocurrency transactions without fully emptying wallets to evade detection.(2026-08-07:clickfix-bnb-chain-etherhiding-malware-campaign)event
↯8a29fe09
Microsoft Security Blog publicly discloses the CryptoBandits malware: a clipboard hijacker polling every 500 milliseconds for cryptocurrency wallet addresses, propagating via USB worm, and routing C2 traffic through Tor. Trojan:Win32/CryptoBandits.A detection name assigned.(2026-06-17:clickfix-bnb-chain-etherhiding-malware-campaign)event
↯c01eba34
Researchers discover the Omnistealer campaign using TRON, Aptos, and BNB Chain blockchains for on-chain payload delivery to steal credentials, cloud account data, passwords, and cryptocurrency wallet contents, demonstrating multi-chain expansion of the EtherHiding model.(2026-04-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
↯a896cb8c
CryptoBandits malware campaign begins activity, distributing clipboard-hijacking and USB-worm components via malicious .lnk payloads. Microsoft later identifies the campaign as active from at least February 2026.(2026-02-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
↯a6cbc76d
Google Threat Intelligence Group (GTIG) reports that DPRK-linked threat actor UNC5342 has adopted the EtherHiding technique in fake job interview social engineering campaigns targeting software developers, marking the first documented nation-state use of the technique.(2025-10-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
↯91028f9d
The Hacker News and Guardz publicly document the EtherHiding technique for the first time, describing it as 'the next level of bulletproof hosting' and attributing it to the ClearFake campaign targeting WordPress sites.(2023-10-16:clickfix-bnb-chain-etherhiding-malware-campaign)event
↯e6262384
ClearFake campaign begins using EtherHiding technique on BNB Smart Chain, storing malicious payload JavaScript inside on-chain smart contracts. Guardz researchers later document this as the first known EtherHiding campaign.(2023-08-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
⌂1972268c
ClickFix BNB Chain EtherHiding Malware Campaignprotocol
↯18c29894
Zenith Security publicly confirmed it would cooperate with investigators and stated it had identified IP-level information about the operators to share with authorities. On-chain analysts BrutalTrade and SpecterAnalyst published wallet address linkages. Alleged prior projects ZinoFinance, Zero-G Finance, and PerfectSwap were identified as linked to the same operator network.(2025-09-27:hypervault-finance)event
↯9bfefc4a
PeckShield publicly flagged 'abnormal withdrawal of ~$3.6M worth of crypto from @hypervaultfi.' Approximately 752 ETH (estimated $3 million) was confirmed deposited into Tornado Cash. Hypervault's website, X account, Discord server, and GitHub repositories were all deleted. The Block, Decrypt, CryptoNews, and other outlets began covering the incident.(2025-09-26:hypervault-finance)event
↯4e238de6
Rug pull executed. All nine Hypervault vaults on HyperEVM were drained by the project operators using privileged contract access. Funds were bridged from Hyperliquid to Ethereum via deBridge.(2025-09-25:hypervault-finance)event
↯8cb4d26f
TVL on Hypervault reached approximately $4.97–6.01 million according to DefiLlama, representing peak depositor exposure ahead of the drain.(2025-09-24:hypervault-finance)event
↯ed0c7702
Zenith Security delivered a private draft audit report to the Hypervault team identifying 42 vulnerabilities — 6 high severity and 10 medium severity — with a recommendation for full re-audit after remediation. The report was never publicly disclosed by the project.(2025-09-21:hypervault-finance)event
↯d83950e5
Hypervault publicly announced that an audit had commenced with Zenith Security, a legitimate audit firm.(2025-09-14:hypervault-finance)event
↯930c7c2a
Community researcher HypingBull publicly warned on X that Hypervault's claimed audits from Spearbit, Pashov, and Code4rena appeared fabricated. Direct contact with Pashov Group returned the response: 'First time I hear the project with this name.' Code4rena's public listing showed no pending Hypervault audit. TVL was approximately $700,000 at time of warning.(2025-09-04:hypervault-finance)event
↯9307dc54
Latest Hacking News and Help Net Security publish detailed analyses of ENCFORGE, including SHA-256 hashes, C2 infrastructure, and mitigation guidance.(2026-07-26:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
↯bd5d1164
Sysdig publishes its ENCFORGE follow-on report detailing the compiled Go ransomware binary targeting AI model infrastructure, confirming operator continuity via the shared Proton Mail address.(2026-07-21:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
↯a155b8ff
TechTimes publishes analysis of what comes after JADEPUFFER, describing the lowered ransomware skill floor and anticipated increase in agentic campaigns.(2026-07-13:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
↯bd3a4f8e
The same JADEPUFFER operator returns with a new compiled Go ransomware binary (ENCFORGE), exploiting the same Langflow CVE and escaping via Docker socket to target AI model files (PyTorch, SafeTensors, GGUF, FAISS, Parquet, etc.) on the host filesystem.(2026-07-03:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
↯7f8097b3
Sysdig publishes its initial JADEPUFFER analysis, describing the operation as the first documented fully agentic ransomware campaign. Approximately 1,050 to 7,000 Langflow instances remain publicly reachable at this date.(2026-07-01:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
Data refreshes every 5 minutes · All metrics derived from Supabase