Skip to main content
Sign in
AVOID.NET

Entity Graph

Browse extracted entities, relationships, and potential duplicates.

Total entities
22,563
Relationships
17,963
Potential duplicates
0

Entities

SEC files civil fraud complaint against MCC International Corp., Emerson Sousa Pires, Luiz Carlos Capuci Jr., CPTLCoin Corp., and Bitchain Exchanges.(2022-04-22:emerson-sousa-pires)event
23a3c8ef
U.S. District Court for the Southern District of Florida issues a temporary restraining order and asset freeze against MCC International Corp., Capuci, and Pires following SEC complaint.(2022-04-21:emerson-sousa-pires)event
0559aa38
EmpiresX stops honoring investor withdrawal requests.(2021-11-01:emerson-sousa-pires)event
e4e705ef
Pires and Goncalves launch EmpiresX (Empires Consulting Corp.) in South Florida, soliciting investors for an alleged cryptocurrency trading platform using a purported algorithmic 'bot'.(2020-09-01:emerson-sousa-pires)event
8bbcfbc2
MCC International Corp. (Mining Capital Coin) allegedly begins selling fraudulent mining packages to investors, promising 1% daily returns. Pires and Capuci are co-founders.(2018-01-01:emerson-sousa-pires)event
97c33b37
Emerson Sousa Piresorganization
b8f90b8a
Judge K. Michael Moore (S.D. Fla.) enters a $46 million default judgment against Capuci, Pires, MCC International, CPTLCoin Corp., and Bitchain Exchanges, comprising ~$28.5M disgorgement, ~$7.8M prejudgment interest, and civil monetary penalties.(2025-08-26:luiz-carlos-capuci-jr)event
31973ca5
U.S. magistrate judge recommends approximately $28 million in disgorgement against Capuci, Pires, and related entities in the SEC civil case.(2025-02-01:luiz-carlos-capuci-jr)event
b0ea1f86
Criminal trial against Capuci begins in Brazil.(2024-08-21:luiz-carlos-capuci-jr)event
e09a6d22
U.S. law firm Wellman & Warren LLP withdraws from representing Capuci, citing inability to pay; local counsel Gregg S. Lerman follows on August 22, 2024.(2024-08-02:luiz-carlos-capuci-jr)event
0795b86c
Brazilian Federal Police launch Operation Yang; Capuci and Pires are arrested. Authorities freeze up to R$300 million (~$55M USD) in bank accounts and block 52 properties across Brazil.(2023-09-13:luiz-carlos-capuci-jr)event
455a47db
U.S. court lifts the stay on the SEC civil case.(2023-06-10:luiz-carlos-capuci-jr)event
5208fdef
Capuci's appeal of the SEC preliminary injunction is denied.(2023-05-31:luiz-carlos-capuci-jr)event
0797dd7b
U.S. court grants SEC permission to serve Capuci via email through his U.S.-based attorneys after international service delays.(2023-03-08:luiz-carlos-capuci-jr)event
2db4962a
Brazilian Federal Police open a criminal investigation based on intelligence provided by U.S. Homeland Security Investigations (HSI).(2022-08-01:luiz-carlos-capuci-jr)event
f94262c1
DOJ unseals indictment against Capuci (Case No. 22-20173-CR-Altonaga, S.D. Fla.) charging conspiracy to commit wire fraud, securities fraud, and international money laundering; maximum exposure of 45 years.(2022-05-05:luiz-carlos-capuci-jr)event
932389dc
U.S. District Court for the Southern District of Florida issues a temporary restraining order and asset freeze against Capuci, Pires, MCC International, CPTLCoin Corp., and Bitchain Exchanges.(2022-04-21:luiz-carlos-capuci-jr)event
61e14b88
MCC International Corp. (Mining Capital Coin) begins selling mining packages to investors, promising 1% daily returns paid weekly for up to 52 weeks.(2018-01-01:luiz-carlos-capuci-jr)event
6e7cff3d
Luiz Carlos Capuci Jr.organization
d5459bf1
U.S. District Court enters a combined $46 million default judgment against MCC International Corp., CPTLCoin Corp., Bitchain Exchanges, Capuci, and Pires, comprising approximately $28.5 million in disgorgement and $7.8 million in prejudgment interest.(2025-08-26:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
ef8d11f2
Brazil's Federal Police launch Operation Yang, executing 25 search and seizure warrants across 8 states; Emerson Pires is reported arrested in Florianopolis; R$300 million in bank accounts frozen and 52 properties blocked.(2023-09-13:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
82be6b15
Brazilian authorities open an independent criminal investigation into MCC founders for alleged money laundering of up to R$300 million.(2022-08-01:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
0c7e47f2
DOJ unseals criminal indictment against Luiz Carlos Capuci Jr. for conspiracy to commit wire fraud, securities fraud, and international money laundering in connection with the alleged $62 million scheme.(2022-05-08:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
3b602ad0
SEC publicly announces fraud charges against MCC International Corp., CPTLCoin Corp., Bitchain Exchanges, Luiz Carlos Capuci Jr., and Emerson Sousa Pires.(2022-05-06:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
57734f28
U.S. District Court for the Southern District of Florida issues a temporary restraining order against all defendants and freezes their assets at the SEC's request.(2022-04-21:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
f31fedae
MCC International Corp. (Mining Capital Coin) begins selling fraudulent mining packages to investors, promising 1% daily returns paid weekly.(2018-01-01:mcc-international-corp-cptlcoin-corp-bitchain-exchanges)event
d6285c62
MCC International Corp / CPTLCoin Corp / Bitchain Exchangesexchange
c4aaab78
7535616d
The Hacker News reports over 250 ClickFix domains using browser fingerprinting to serve platform-specific macOS malware lures, indicating campaign infrastructure has scaled to hundreds of distinct lure domains.(2026-08-08:clickfix-bnb-chain-etherhiding-malware-campaign)event
d13d97df
Huntress researchers separately document a Go-based macOS infostealer delivered via ClickFix attacks, capable of partially redirecting cryptocurrency transactions without fully emptying wallets to evade detection.(2026-08-07:clickfix-bnb-chain-etherhiding-malware-campaign)event
21892432
Microsoft Security Blog publicly discloses the CryptoBandits malware: a clipboard hijacker polling every 500 milliseconds for cryptocurrency wallet addresses, propagating via USB worm, and routing C2 traffic through Tor. Trojan:Win32/CryptoBandits.A detection name assigned.(2026-06-17:clickfix-bnb-chain-etherhiding-malware-campaign)event
8a29fe09
Researchers discover the Omnistealer campaign using TRON, Aptos, and BNB Chain blockchains for on-chain payload delivery to steal credentials, cloud account data, passwords, and cryptocurrency wallet contents, demonstrating multi-chain expansion of the EtherHiding model.(2026-04-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
c01eba34
CryptoBandits malware campaign begins activity, distributing clipboard-hijacking and USB-worm components via malicious .lnk payloads. Microsoft later identifies the campaign as active from at least February 2026.(2026-02-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
a896cb8c
Google Threat Intelligence Group (GTIG) reports that DPRK-linked threat actor UNC5342 has adopted the EtherHiding technique in fake job interview social engineering campaigns targeting software developers, marking the first documented nation-state use of the technique.(2025-10-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
a6cbc76d
The Hacker News and Guardz publicly document the EtherHiding technique for the first time, describing it as 'the next level of bulletproof hosting' and attributing it to the ClearFake campaign targeting WordPress sites.(2023-10-16:clickfix-bnb-chain-etherhiding-malware-campaign)event
91028f9d
ClearFake campaign begins using EtherHiding technique on BNB Smart Chain, storing malicious payload JavaScript inside on-chain smart contracts. Guardz researchers later document this as the first known EtherHiding campaign.(2023-08-01:clickfix-bnb-chain-etherhiding-malware-campaign)event
e6262384
ClickFix BNB Chain EtherHiding Malware Campaignprotocol
1972268c
Zenith Security publicly confirmed it would cooperate with investigators and stated it had identified IP-level information about the operators to share with authorities. On-chain analysts BrutalTrade and SpecterAnalyst published wallet address linkages. Alleged prior projects ZinoFinance, Zero-G Finance, and PerfectSwap were identified as linked to the same operator network.(2025-09-27:hypervault-finance)event
18c29894
PeckShield publicly flagged 'abnormal withdrawal of ~$3.6M worth of crypto from @hypervaultfi.' Approximately 752 ETH (estimated $3 million) was confirmed deposited into Tornado Cash. Hypervault's website, X account, Discord server, and GitHub repositories were all deleted. The Block, Decrypt, CryptoNews, and other outlets began covering the incident.(2025-09-26:hypervault-finance)event
9bfefc4a
Rug pull executed. All nine Hypervault vaults on HyperEVM were drained by the project operators using privileged contract access. Funds were bridged from Hyperliquid to Ethereum via deBridge.(2025-09-25:hypervault-finance)event
4e238de6
TVL on Hypervault reached approximately $4.97–6.01 million according to DefiLlama, representing peak depositor exposure ahead of the drain.(2025-09-24:hypervault-finance)event
8cb4d26f
Zenith Security delivered a private draft audit report to the Hypervault team identifying 42 vulnerabilities — 6 high severity and 10 medium severity — with a recommendation for full re-audit after remediation. The report was never publicly disclosed by the project.(2025-09-21:hypervault-finance)event
ed0c7702
Hypervault publicly announced that an audit had commenced with Zenith Security, a legitimate audit firm.(2025-09-14:hypervault-finance)event
d83950e5
Community researcher HypingBull publicly warned on X that Hypervault's claimed audits from Spearbit, Pashov, and Code4rena appeared fabricated. Direct contact with Pashov Group returned the response: 'First time I hear the project with this name.' Code4rena's public listing showed no pending Hypervault audit. TVL was approximately $700,000 at time of warning.(2025-09-04:hypervault-finance)event
930c7c2a
Hypervault Financeprotocol
5a5ff7f0
Latest Hacking News and Help Net Security publish detailed analyses of ENCFORGE, including SHA-256 hashes, C2 infrastructure, and mitigation guidance.(2026-07-26:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
9307dc54
Sysdig publishes its ENCFORGE follow-on report detailing the compiled Go ransomware binary targeting AI model infrastructure, confirming operator continuity via the shared Proton Mail address.(2026-07-21:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
bd5d1164
TechTimes publishes analysis of what comes after JADEPUFFER, describing the lowered ransomware skill floor and anticipated increase in agentic campaigns.(2026-07-13:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
a155b8ff
The same JADEPUFFER operator returns with a new compiled Go ransomware binary (ENCFORGE), exploiting the same Langflow CVE and escaping via Docker socket to target AI model files (PyTorch, SafeTensors, GGUF, FAISS, Parquet, etc.) on the host filesystem.(2026-07-03:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
bd3a4f8e
Sysdig publishes its initial JADEPUFFER analysis, describing the operation as the first documented fully agentic ransomware campaign. Approximately 1,050 to 7,000 Langflow instances remain publicly reachable at this date.(2026-07-01:jadepuffer-first-fully-autonomous-ai-ransomware-targeting-crypto-wallet-keys)event
7f8097b3
Data refreshes every 5 minutes · All metrics derived from Supabase