Threat Intelligence
Threat intelligence here means the observable behaviour of fraud operations: the platforms they deploy, the infrastructure they reuse, the scripts and escalation patterns applied to targets, and the indicators that appear before a loss is realised.
Briefings are written for compliance functions, counsel and investigators who need pattern-level context to assess an individual matter.
5 indexed resources
Scope of this topic
- ·Fraud platform and hosting infrastructure patterns
- ·Social engineering escalation and script analysis
- ·Indicators observable before and during a loss event
- ·Reuse of infrastructure across apparently unrelated matters
- ·Risk framing for compliance and onboarding review
Threat Intelligence resources
- Threat Intelligence · Risk · 3 min read
Warning Signs of a Cryptocurrency Investment Scam
The structural warning signs that recur across fraudulent cryptocurrency investment platforms, documented from investigative casework.
Updated 2026-08-03 - Threat Intelligence · Risk · 3 min read
How Fake Investment Platforms Are Built
The technical and operational anatomy of fraudulent investment platforms: cloned interfaces, shared infrastructure and centralised deposit routing.
Updated 2026-08-03 - Threat Intelligence · Risk · 3 min read
Pig Butchering Scams: Structure and Investigation
How long-term relationship investment fraud operates, why it succeeds, and how these networks are investigated on-chain and off-chain.
Updated 2026-08-03 - Threat Intelligence · Risk · 3 min read
Cryptocurrency Phishing and Wallet Drainers
How crypto phishing and wallet-drainer attacks work, what they leave on-chain, and how the resulting transfers are investigated.
Updated 2026-08-03 - Case Study · Cybercrime · 3 min read
Financial Cybercrime Analysis
A supplier payment was diverted after an intrusion into a shared mailbox, combining a technical incident with a financial loss.
Updated 2026-08-03
Frequently asked questions
- Is this threat intelligence attributable to named actors?
- Published briefings describe behaviour and infrastructure patterns. Named attribution of individuals or groups is not published; it belongs in case-specific work product produced for counsel or authorities.
- How current is the material?
- Briefings carry an explicit update date and describe patterns observed in engagements up to that point. Infrastructure changes rapidly, so indicators should be treated as contextual rather than definitive.
Continue across the Intelligence Center
- Blockchain IntelligenceOn-chain tracing, wallet attribution, exchange intelligence and cross-chain analysis material.
- Financial CrimeInvestment fraud typologies, payment-chain reconstruction and regulatory case structuring.
- ResearchTechnical publications on investigative technique, on-chain behaviour and evidentiary standards.
- Digital ForensicsEvidence preservation, metadata analysis, artefact examination and chain-of-custody standards.
Related intelligence
Intelligence Center
- Cyber Intelligence
- Blockchain Investigations
- Digital Forensics
The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.
Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.
About the research team