Check Point reported an AI-enabled investment fraud campaign branded as OPCOPRO that lures victims via unsolicited SMS, social media outreach, and ads impersonating legitimate financial firms (including messages posing as Goldman Sachs). Targets are funneled into private WhatsApp groups where the scam builds trust over weeks through daily “market” content and staged social proof: group “leaders” (e.g., Professor James and an assistant) use AI-generated profile images, while most of the ~90 apparent members are automated accounts that post uniform, enthusiastic reactions and fabricated profit screenshots to create a convincing community.
After grooming, victims are directed to install the OPCOPRO mobile app—reported as available via official app marketplaces to increase credibility (including an Android package cited as com.yme.opcopro)—and are presented with partnership claims and regulatory-looking documents to reinforce legitimacy. The app is used to collect sensitive information, including KYC-style data and government ID photos, which increases downstream risk beyond immediate financial loss (e.g., enabling recovery fraud and SIM-swap attempts). The campaign highlights how AI is being used to industrialize scams by cheaply generating believable identities, content, and “business” artifacts that mimic legitimate digital investment platforms.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Check Point publicly reported that OPCOPRO is an industrialized, multilingual scam framework that uses AI-generated personas and bot-driven social engineering rather than malware to defraud victims over time. The researchers warned that the stolen identity data could support additional abuse such as SIM swapping, help-desk social engineering, account takeover, and recovery scams.
Victims were instructed to install the O-PCOPRO mobile app from official app stores, complete KYC steps including ID photos and liveness selfies, and then deposit money based on promises of extreme returns. Check Point found the app lacked real trading functionality and mainly acted as a WebView showing manipulated figures while collecting identity data for possible follow-on fraud.
After initial contact, targets were directed into private WhatsApp groups led by fictitious personas such as “Professor James” and “Lily,” with AI-generated profile images and automated participants posting repetitive messages and fake profit screenshots to build trust. Researchers said the groups were largely populated by bots and internet-based phone numbers that could not be reached by voice calls.
Threat actors launched a large-scale investment scam using unsolicited SMS, social media messages, and Google Ads impersonating legitimate financial firms such as Goldman Sachs to attract victims with promises of high returns. The outreach funneled targets toward a fraudulent investment operation branded as OPCOPRO.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.