Crypto Drainer & Fake AML Verification Operation
717Team operates a fake AML verification and wallet drainer scheme on the TRON/TRX network. Victims are directed to phishing domains (checkscore.cc, amlbot.pw, wallet-invoice.pw, etc.) posing as legitimate AML/KYC verification services. Upon connecting their wallets, a smart contract drainer steals all USDT. The operation uses @withdraw_717_bot for automated payouts (~70% to workers). Coordination happens in Telegram with 125+ participants.
Telegram ID: 7149807602
0x9943777f44053566fFa9d43869D33D1B48387A3B
| Date | Wallet | Amount | Domain | IP | Geo | Status |
|---|---|---|---|---|---|---|
| Jan 23 | TQGLaa...KG55 | 2,200.40 | cryptomus-payment.com | 2402:4000:... | Colombo, Sri Lanka | DRAINED |
| Jan 26 | TRgGey...QJA | 203.00 | cryptomus-payment.com | 94.246.204.214 | Kohtla-Järve, Estonia | DRAINED |
| Jan 10 | TVgTrv...wiTU | 133.55 | amlbot.pw | 185.138.166.85 | Amsterdam, Netherlands | DRAINED |
| Jan 29 | TNDRMe...WRi | 102.39 | cryptomus-payment.com | 2403:6200:... | Phuket, Thailand | APPROVED |
| Jan 18 | TRTSwJ...1vZv | 90.01 | cryptomus-invoice.com | 88.252.231.95 | Erzincan, Turkey | DRAINED |
| Jan 28 | TDp7XR...JLL5A | 77.94 | checkscore.cc | 91.239.157.242 | Frankfurt, Germany | DRAINED |
| Jan 29 | TELbin...EHeh | 39.13 | cryptomus.ltd | 202.58.197.64 | Denpasar, Bali, Indonesia | DRAINED |
| Jan 26 | TQQaP8...Ach | 16.19 | cryptomus-payment.com | 2001:e60:... | Gwanak-gu, Seoul, South Korea | APPROVED |
| Jan 26 | TRTSwJ...1vZv | 38.83 | cryptomus-invoice.com | 88.252.231.95 | Erzincan, Turkey | DEPOSIT |
| Jan 15 | TGtALv...7gkU | 9.00 | amlbot.pw | — | — | APPROVED |
| Jan 28 | TAnje8...Dwk9 | 4.23 | wallet-invoice.pw | 2a02:8440:... | Metz, France | DEPOSIT |
| Jan 22 | TNDRMe...WRi | 2.39 | cryptomus-payment.com | 2403:6200:... | Phuket, Thailand | APPROVED |
| Jan 24 | TVzwRJ...bmNo | 1.01 | cryptomus-payment.com | 146.70.193.15 | Belgrade, Serbia | APPROVED |
| Date | Wallet | Domain | IP | Location | Browser |
|---|
| # | TX Hash | Link |
|---|
| # | Wallet Address | Tronscan |
|---|
| User ID | Display Name |
|---|
Intelligence collected by PhishDestroy | GitHub
This data is provided for law enforcement, security research, and anti-fraud purposes.