Researchers reported an active cryptocurrency scam using a polished “Google Coin” presale website paired with a fake chatbot impersonating Google’s Gemini AI assistant. The site presents “Google Coin” as a legitimate Google-backed token (Google has no such cryptocurrency) and uses Gemini-like branding cues (e.g., sparkle icon and “Online” status) to build trust while guiding victims toward irreversible crypto payments to attacker-controlled wallets.
The impersonating chatbot is designed to function as an automated closer: it answers investment questions, provides specific (fabricated) return projections (e.g., presale price vs. expected listing price), and persistently steers users toward purchase. Analysis noted the bot maintained a consistent “official helper” persona while refusing verifiable company details (registered entity, regulator/license, audit firm, official email) and deflecting concerns with vague claims about “transparency” and “security,” mirroring high-pressure social engineering tactics previously requiring human operators.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Malwarebytes Labs published details of the scam, describing how the chatbot delivered tailored return projections, deflected due-diligence questions, and sometimes escalated users to an unnamed 'manager.' The report also highlighted the operation as an example of AI-enabled social engineering at scale and shared scam wallet addresses as indicators of compromise.
Security researchers reported a cryptocurrency presale scam centered on a fictitious token called 'Google Coin.' The site impersonated Google branding and used a counterfeit chatbot posing as Google's Gemini AI assistant to persuade visitors to buy the nonexistent coin with cryptocurrency payments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcemalwarebytes.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.