FBI Warns: Scammers Impersonating IC3 Employees to Defraud Victims

FBI Warns of Sophisticated Phishing Campaign Impersonating IC3 Employees

The Federal Bureau of Investigation (FBI) has issued an urgent alert regarding a new phishing campaign in which cybercriminals impersonate employees of the Internet Crime Complaint Center (IC3) to defraud victims.

First identified in early April 2025, the campaign uses spoofed emails that appear to originate from legitimate IC3 domains. These messages often claim to offer help with prior fraud reports or promise financial recovery services.

Using advanced social engineering tactics, attackers gain victims’ trust by referencing publicly available details or past complaints. Victims are then urged to install so-called “verification software,” which is, in reality, a Remote Access Trojan (RAT).

Initial findings suggest that the attackers are specifically targeting individuals who have previously filed IC3 reports, possibly by exploiting a data breach or mining public records.

IC3 analysts have flagged the malware’s advanced capabilities, noting that it employs multi-stage encryption and fileless execution to avoid antivirus detection.

“The threat actors have implemented multi-stage encryption and fileless execution methods that make traditional detection extremely difficult,” said Maria Chen, Senior IC3 Cyber Analyst.

To date, more than 230 individuals across the U.S. have been affected, resulting in financial losses exceeding $1.2 million in just three weeks.


Infection Method Details

The primary infection vector is a deceptive PDF attachment that appears official and uses FBI branding. When opened, it silently runs PowerShell commands in the background:


More Articles & Posts