Ishaan Gupta - is an ex student of Wroclaw University of Science and Technology (Organizational Management 2016 - 2019), currently residing in India. The attacker has transitioned from simple spam to a complex multi-vector campaign. He is now combining account farming (using multiple distinct Gmail, iCloud, and Mail ru addresses), identity spoofing (international names), bypassing spam filters with calendar invites, and third-party AI tooling abuse to ensure delivery into employees mailboxes. Tactics used by scammer: Coordinated Harassment Campaign Account Farming Identity Deception / Impersonation Calendar Phishing / Invitation Abuse Bypassing Corporate Spam Filters Social Engineering {Malicious emotional manipulation, Fabricated sob stories, Guilt-tripping the victims , Exploiting empathy for financial/professional gain}
Protection Tips
- • Never send money to strangers online
- • Be cautious of crypto & gift card requests
- • Verify identities through video calls
- • Search usernames before engaging
Submit a report to help protect others
Related Reports
Fake id
Guoanbu SCAM — @weliketohunt, @rpp33, @synmaestr0 @weliketohunt (Telegram ID: 8735722615), @rpp33 (Telegram ID: 8920257159), @synmaestr0 (Telegram ID: 8748715371) and the person without a username but with the nickname ***** (Telegram ID: 8488455504) are one and the same individual. Using the ***** account, he initiates contact and states that he can be trusted. He then asks to move the conversation to another account, @weliketohunt. There he scams people. In my case he took $477 for 15 days of botnet access. Three days later he demanded additional payment. I refused to pay again, after which he removed my account from his botnet and deleted the message history on telegram. I asked my friend whether he knew this person. My friend replied that he did — that this is a long-time scammer who has been scamming everyone for a long time. The main account of this scammer is @rpp33. My friend wrote to him on his main account @rpp33, and this bastard @rpp33 said that he would restore my access only if I paid him again. His C2: 176.65.148.222:1975 (Telnet). Full logs here: https://t.me/s/bctnet_scam
Is ka content sarieam damki karta haa or loogu ko tang karta haa
Report #100263 · Cluster #cluster_1784707570655