Serbia’s National CERT warned that fraudsters are using the OKEGreen platform and related domains including okegreen.com, okaiv.com, and okegreen.cc to lure victims with promises of quick profits from cryptocurrency-linked investments and easy online earnings. The scheme is promoted heavily through social media ads that collect phone numbers, after which supposed brokers, assistants, mentors, or investment advisers contact targets and steer them into fake investment activity, referral programs, assigned tasks, and bogus claims that simple clicks can help train artificial intelligence tools for payment.
A similar warning from CERT-MU in Mauritius described fake online trading and investment scams in which callers impersonate crypto and forex traders, persuade victims to hand over money and identity or banking documents, and display fabricated trading dashboards showing false gains before demanding extra payments such as taxes to release withdrawals. Both alerts emphasize that the operations rely on impersonation, false profit claims, and document harvesting, with Serbian authorities urging affected users to contact police and replace submitted identity documents, while Mauritian authorities advised victims to notify regulators, police, and their banks.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
CERT-MU issued a high-severity warning about fake online trading and investment scams targeting Mauritian users. The scams involved unsolicited calls from fraudsters posing as cryptocurrency and forex traders, fake account gains, and demands for extra tax payments before withdrawals.
Serbia’s National CERT warned of a new wave of online fraud tied to the OKEGreen platform, promoted through social media ads and follow-up contact from supposed brokers, assistants, advisors, or mentors. The notice identified okegreen.com, okaiv.com, and okegreen.cc as active platform domains and advised affected users who submitted identity documents to contact police and seek replacement documents.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.