Social Engineering Enterprise is a financially motivated cybercriminal organization focused on large-scale cryptocurrency theft from individual holders. The group emerged in 2023 and has been linked to thefts totaling more than $260 million. Reporting and court allegations identify Singaporean national Malone Lam as a founder, with additional members operating from multiple U.S. states including California, Connecticut, New York, Florida, and Texas, indicating a geographically distributed criminal network rather than a state-sponsored actor. The group specialized in identifying wealthy cryptocurrency owners and stealing funds through a combination of cyber-enabled fraud and real-world coercive crime. Its operations included obtaining hacked or illicitly purchased databases of cryptocurrency holders, compiling target lists, impersonating customer support or representatives of major technology companies and cryptocurrency services, and persuading victims to disclose credentials, account details, or wallet access information. The organization also conducted physical thefts and home invasions to obtain devices or hardware wallets associated with victims’ cryptocurrency holdings. Operationally, the enterprise appears to have used a division of labor that included database hackers, organizers, target selectors, callers, money launderers, and residential burglars. Members coordinated through encrypted messaging platforms, rotated identities, used false identities to rent or purchase luxury properties that supported operations, and took steps to destroy devices and conceal evidence after arrests. Stolen cryptocurrency was laundered through exchanges and mixers and converted into fiat currency, with proceeds spent on luxury goods, vehicles, travel, and high-end real estate rentals. Known publicly identified members include Malone Lam and Evan Tangeman, the latter of whom pleaded guilty to RICO conspiracy charges tied to laundering proceeds and supporting the group’s infrastructure. The actor is notable for blending social engineering, credential theft, crypto theft, money laundering, defense evasion, and physical intrusion against high-value individual targets in the cryptocurrency ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cybercriminal organization focused on identifying and robbing high-value cryptocurrency owners through social engineering, stolen or dark-web-purchased databases, digital theft, physical theft, and cryptocurrency laundering.
Criminal group accused of large-scale cryptocurrency theft via social engineering: using hacked databases to identify wealthy targets, impersonating cryptocurrency exchanges to trick victims into transferring funds, and in some cases organizing home break-ins to steal hardware wallets/keys.
A criminal gang conducting large-scale cryptocurrency thefts through social engineering, database hacking, physical burglaries, and money laundering. They targeted individuals with significant crypto holdings, using a mix of online and physical tactics to steal funds and launder proceeds.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.