A newly uncovered phishing campaign, known as “Power Parasites,” has been aggressively targeting leading energy corporations and global brands since 2024, according to a detailed threat report published this week.
This persistent operation leverages the trusted names and identities of major energy players — including Siemens Energy, Schneider Electric, EDF Energy, Repsol S.A., and Suncor Energy — to execute sophisticated investment fraud schemes and fake job recruitment scams.

The threat actors have built a sprawling network of more than 150 active domains, carefully crafted to mimic legitimate businesses, with a primary focus on victims across Asian countries such as Bangladesh, Nepal, and India.
Victims are targeted through a combination of fake websites, social media groups, and Telegram channels, often featuring localized content in English, Portuguese, Spanish, Indonesian, Arabic, and Bangla to boost credibility and engagement.
Researchers at Silent Push observed that the attackers use a broad “spray and pray” strategy — simultaneously exploiting multiple brand identities while deploying a large volume of fraudulent websites to expand their reach.
Infrastructure analysis revealed that the threat actors register domains containing keywords such as “SE” (for Siemens Energy) and “AMD” (for Advanced Micro Devices), paired with various domain suffixes to form addresses like “sehub.top” and “amd-biz.mom,” creating identifiable naming patterns across their network.
The attackers rely on two primary social engineering tactics. In the investment scam variant, victims are enticed with promises of high returns via fake investment platforms falsely endorsed by reputable energy companies. In the job scam variant, individuals are lured with fraudulent employment opportunities at well-known corporations, prompting them to submit sensitive information such as bank details, identification documents, and voided checks under the guise of an onboarding process.
Infection Mechanism and Technical Infrastructure
The Power Parasites campaign is underpinned by a sophisticated technical infrastructure optimized for widespread distribution and evasion of detection.
Deceptive websites across the campaign consistently follow a common template, notably featuring login pages with an “Invite code” field — a classic tactic used in investment scams to create an illusion of exclusivity and urgency.
Promotion efforts have expanded to YouTube, where videos in multiple languages direct viewers to malicious domains like “se-renewables.info,” with titles promising easy earnings. For instance, one Bangla-translated video encourages users to “Earn free money from new sites,” showcasing the attackers’ multilingual, global outreach.
Technical fingerprinting by security researchers uncovered shared characteristics across the phishing sites’ infrastructure, allowing the attackers to rapidly spin up new domains as existing ones are taken down.
Telegram has also been weaponized, with channels impersonating Siemens Energy (“siemensenergy”) used to spread malicious links — though many of these channels have since been banned or removed.
In response to the ongoing campaign, Siemens Energy has publicly warned users, emphasizing that the company “does not operate any investment platforms” and “does not ask for fees prior to, during, or after the application process.”

Likewise, Repsol Energy has launched a Fraud Alert page warning against scams that leverage artificial intelligence to impersonate members of their executive team.




