Savvy Seahorse is a financially motivated scam operator associated with large-scale cryptocurrency investment fraud campaigns that combine malvertising with pig-butchering-style social engineering. The activity uses social media advertising, including Facebook ads, to lure victims to fake investment platforms and related lure sites, often impersonating financial experts or promoting purported AI-driven investing opportunities. Victims are then funneled into legitimate messaging applications, where one-on-one and group-chat interactions build trust through scripted conversations, fabricated success stories, and escalating investment prompts before culminating in direct fund transfers and fraudulent fee demands to release fictitious profits. The operation demonstrates substantial infrastructure scale and reuse, with thousands of domains linked to the broader ecosystem, extensive clustering, and evidence of shared website frameworks or kits. Reporting also associates Savvy Seahorse with the use of DNS CNAME-based infrastructure techniques in support of victim redirection and campaign enablement. The campaigns appear highly scalable and partially automated, with indications of AI-assisted or otherwise automated chat engagement across languages and time zones. Targeting has been especially pronounced in Asia, particularly Japan, while expansion into additional language markets indicates a broader international fraud model. In sector terms, the activity aligns with targeting of finance-oriented audiences through fake investment themes rather than intrusion-focused espionage or disruptive operations. Savvy Seahorse was newly observed in finance-sector threat reporting during the referenced period.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newly observed actor in the current finance-sector campaign period.
Malvertising-driven investment fraud actor previously documented using Facebook ads and DNS CNAME-based infrastructure to funnel victims to fake investment platforms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.