U.S. prosecutors charged Zhuoying Chen and Haojie Zhang for allegedly running a New York-based money laundering network that processed proceeds from cyber-enabled investment fraud scams. An unsealed indictment alleges the pair managed more than a dozen people in Queens and Brooklyn between 2020 and 2022, using roughly 140 bank accounts linked to about 45 shell companies to move at least $43 million before transferring the funds to bank accounts in China.
Authorities said the underlying scams used social media and messaging platforms to build trust with victims, steer them into fake investment opportunities, and extract additional payments by showing fabricated profits, a pattern commonly associated with pig-butchering fraud. The charges come amid a broader U.S. crackdown on investment scams after the FBI reported that such schemes accounted for 49% of scam-related incidents in 2025 and caused $8.6 billion in reported losses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
U.S. prosecutors charged Zhuoying Chen and Haojie Zhang for allegedly operating a large-scale money laundering network linked to cyber-enabled investment fraud scams. The charges were described as part of a broader U.S. crackdown on pig-butchering and investment fraud.
According to the indictment, Zhuoying Chen and Haojie Zhang allegedly managed more than a dozen people in Queens and Brooklyn and used roughly 140 bank accounts tied to about 45 shell companies to move proceeds from cyber-enabled investment fraud scams. Prosecutors allege the network operated from 2020 to 2022 and transferred at least $43 million to bank accounts in China.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.