Scammers are using fake crypto AML checkers to drain your wallet

Scammers are using fake crypto AML checkers to drain your wallet
Scammers are using fake AML wallet-checking sites that mimic legitimate services like AMLBot to trick users into connecting wallets and approving malicious transactions. The scheme relies on fake progress screens, fabricated fees, and misleading “Clean, Low Risk” results to steal crypto or gain access to token permissions. #AMLBot #AML Check #Browser Guard

Keypoints

  • Fake AML checker sites impersonate legitimate wallet-screening services such as AMLBot and “AML Check.”
  • The scam tries to lure victims into connecting their wallets instead of simply entering a public address.
  • After a wallet connects, scammers can tailor the attack using the victim’s public address and asset information.
  • Some sites display fake progress bars, compliance messages, and bogus fee prompts to appear legitimate.
  • Victims may be pushed to approve malicious transactions, grant token access, or share recovery phrases/private keys.
  • If a wallet was connected, approved, or exposed, users should disconnect, revoke permissions, move funds, or treat the wallet as compromised.
  • Users are advised to verify website addresses carefully and avoid any service that asks for unexpected wallet access or crypto transfers.

MITRE Techniques

  • [T1566 ] Phishing – Fake AML checker sites lure users into interacting with deceptive pages that imitate legitimate services (‘The site is designed to get the victim to approve a transaction generated by the scammers.’).
  • [T1204 ] User Execution – Victims are manipulated into clicking Retry, connecting wallets, and approving transactions on the fake site (‘Clicking Retry plays the same progress animation again’).
  • [T1056 ] Input Capture – The scam may collect sensitive wallet information when users enter it into the site (‘If you entered your recovery phrase or private key: Treat the wallet as compromised’).
  • [T1552 ] Unsecured Credentials – Recovery phrases and private keys are targeted as secrets that can be stolen or abused (‘If you entered your recovery phrase or private key’).
  • [T1106 ] Native API – The scam relies on wallet signing/transaction approval mechanisms to execute unauthorized actions (‘confirm a transaction or signed something you didn’t understand’).
  • [T1091 ] Replication Through Removable Media – Not mentioned as a technique in the article.

Indicators of Compromise

  • [Domains] Fake AML checker websites used to impersonate legitimate services – amlbot-clear[.]com, audittrust[.]shop, and other similar scam domains
  • [Domains] Additional malicious lookalike sites mentioned as examples – bitget-aml[.]com, search-aml[.]net, swapstoken[.]app


Read more: https://www.malwarebytes.com/blog/threat-intel/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet