Fake Crypto AML Checker Infrastructure
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
A coordinated network of fraudulent websites impersonating legitimate anti-money laundering (AML) compliance tools — most prominently AMLBot — was publicly documented by Malwarebytes on August 19, 2026. The sites simulate wallet-risk screening workflows to social-engineer users into connecting wallets and signing drainer transactions, in some cases also charging small upfront 'verification fees.' The campaign is notable for targeting security-conscious users who are actively trying to verify their own wallet safety, and for the systematic reuse of a shared malicious site template rebranded under multiple names and logos.
Connected Entities
1 entities · 10 linked investigationsTimeline(6 events)
2025-04-16
AMLBot publishes initial warning on its official blog about fraudulent sites and Telegram accounts impersonating its brand, requesting wallet access and upfront payments.
AMLBot Blog2025-03-26
PCrisk publishes removal guide for fake AMLBot website scam, identifying domains including amlbot.seize[.]report, amlbot[.]sale, amlbotchecks[.]com, and aml-safety[.]app, with IP 104.26.9.244.
PCrisk2025-06-26
PCrisk publishes second removal guide documenting a distinct cluster of fake AMLBot domains including amlbotchecking[.]com, aml-bot.co[.]com, aml-safety[.]one, amlnix[.]com, and amlbot[.]club, with IP 104.21.15.211.
PCrisk2025-11-10
AMLBot updates its official warning blog post, indicating the impersonation campaign has persisted for at least seven months.
AMLBot Blog2026-06-02
PCrisk updates its second removal guide, confirming the second domain cluster remains active.
PCrisk2026-08-19
Malwarebytes threat researcher Stefan Dasic publishes a report on the active fake AML checker campaign, documenting AMLBot impersonation, 'AML Check' generic branding, fake progress indicators, fabricated scan results, small upfront verification fees, and wallet drainer mechanics. Report corroborated same day by Decrypt, Security Boulevard, Cryptopolitan, and Coin-Turk.
MalwarebytesDecision Log
- #3review revise-13⛓ pending8/25/2026, 2:47:05 AMhash: 6zHNS1fCJzmsQctuzJQ6DsM6nCdQnh4pn5xKmhYK6xi6
- #2review⛓ pending8/25/2026, 2:47:05 AMhash: 5xspGLCvnbJ4SjNHxQEmzw5CTcKbtJUMZKbWisVqoxqj
- #1publish⛓ pending8/24/2026, 11:04:14 PMhash: 8yHLLNRvtdyAk188DoJGRsNkfvxZZ6trG7yX8iEr26aN
8 of 9 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/24/2026, 11:04:04 PM
last updated: 8/25/2026, 3:01:56 AM
avoid.net — verified advice for a post-truth world