A threat actor using the handle xrep is advertising a ready-made cryptocurrency scam kit on a cybercrime forum for about $500, packaging phishing, social engineering, and payment fraud into a turnkey service. Researchers said the kit impersonates Tesla and promotes a fake $TSLA token presale aimed at X users through a polished multilingual website, personalized prompts, countdown timers, scarcity messaging, and a fake investment dashboard designed to pressure victims into sending cryptocurrency.
The package reportedly includes an administrative panel that lets operators track victims, capture X usernames and geolocation data, check wallet values, harvest 12-word recovery phrases, and divert payments to attacker-controlled wallet addresses. It can also falsify account balances to encourage larger deposits and support follow-on fraud such as bogus network-fee requests, giving low-skill criminals a professional scam-in-a-box that can quickly launch convincing crypto investment campaigns.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
The seller behind the scam kit, using the handle xrep, had been active on the underground forum since March 2026 and built a positive reputation there. The account specialized in packaged scam tools related to X.
Malwarebytes researchers discovered the Tesla-themed $TSLA scam project on a high-profile cybercrime forum on May 16. The offering was a $500 turnkey kit combining phishing, social engineering, and fraudulent payment flows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.