OSINT Investment Scam Domain Intelligence Link Analysis

Leveraging Open-Source Intelligence to Combat Cryptocurrency Investment Scams

Cartoon illustration of a magnifying glass hovering over a network of connected open-source intelligence nodes representing social media, domain and contact data sources
Co-authored with: Abraham Berkman (Breadcrumbs, Singapore) and Louise Leenen (University of the Western Cape / CAIR). Presented at the European Conference on Cyber Warfare and Security (ECCWS 2026) as a direct follow-up to the authors' earlier study, "Evaluating an Investigative Process for Cryptocurrency-Related Crimes" — this paper picks up exactly where that one left off, applying deeper off-chain, open-source intelligence (OSINT) enrichment to the same case now that on-chain tracing alone had reached its practical limits.

The previous paper in this series concluded that the off-chain analysis component of the authors' proposed cryptocurrency crime investigation process needed more depth — clearer technique guidance and worked examples of how open-source intelligence can actually take an investigation from a pile of transaction data to a human suspect. This paper is that follow-up. It returns to the same fraudulent investment platform, here referred to openly as RSI-Platform, and works through a structured, iterative off-chain enrichment cycle to see how far OSINT alone can push an investigation once the blockchain trail runs cold at an exchange boundary.

Introduction

On-chain analysis is good at answering "where did the money go" — but it is frequently unable to answer "who moved it." Once stolen funds land inside a centralised exchange, the public ledger goes dark, and the only way forward is a Section 205-style subpoena, or open-source intelligence applied to whatever off-chain fragments the victim and investigators already hold: a domain name, a handful of phone numbers, some alias names, an email address, chat logs. This paper draws a distinction between passive OSINT — gathering information from public sources without directly interacting with a target — and active OSINT, which involves engaging a target directly (typically via an undercover profile), and which requires explicit law enforcement authorisation because of the risk of tipping off a suspect. Everything described in this paper is passive OSINT.

Case Background

RSI-Platform is the same fraudulent CFD and cryptocurrency trading platform examined in the authors' prior paper, where an elderly South African woman was persuaded to hand over close to two years of pension savings believing she was invested in a legitimate, UK-based trading entity. That earlier study traced the stolen Bitcoin through VALR, Kyrrex.com and CoinPayments.net using the tool Breadcrumbs, but the trail eventually reached exchange boundaries the authors could not push past without further subpoenas — and, more importantly, could not connect back to a specific human being.

This paper sets two objectives. First, to determine whether a disciplined, iterative OSINT enrichment cycle can meaningfully extend an investigation once on-chain tracing has plateaued — turning fragments such as a domain name, phone numbers and alias names into a workable suspect network. Second, to test whether that enrichment cycle, applied to this specific case, is sufficient to identify the actual human operator(s) behind RSI-Platform. Several indicators pointed toward a syndicated operation rather than a lone scammer from the outset: multiple VOIP lines and mobile numbers routed through different providers, a cluster of alias names used interchangeably across WhatsApp, Telegram and Snapchat, and a pattern of consumer complaints referencing the same names under what appeared to be at least two prior platform rebrands.

The Investigation Process

The underlying five-phase process — data collection, analysis, theory development and validation, suspect identification and reasonable grounds, and legal action — is unchanged from the authors' earlier work. This paper's contribution sits inside the analysis phase, where it proposes a tighter, explicitly iterative three-step cycle for off-chain evidence: Evidence Overview and Processing, Evidence Enrichment and Processing, and Theory Development and Validation — looping back on itself as many times as needed, with each pass feeding new nodes into a running link-analysis diagram, until the analyst either reaches a workable theory or exhausts the available leads.

Flowchart of the OSINT investigation process showing Initial Evidence feeding into Evidence Overview and Processing, then Evidence Enrichment and Processing, then Theory Development, looping back and feeding a Link Analysis Diagram at each stage, ending in a Done circle
Figure 1. OSINT Investigation Process

Data Collection

As in the prior paper, the "opening a case" step was already complete by the time the authors became involved. The off-chain inputs carried forward for this study were (redacted): the domain rsi-platform.io; a list of SA and UK phone numbers used by individuals contacting the victim over WhatsApp, Telegram and Snapchat; the same alias names from the earlier investigation; the VALR payment-routing address; a physical address on Bank St, London; and an email address tied to the platform's own website footer.

Evidence Overview and Processing

Domain name findings. The Wayback Machine's archive of rsi-platform.io returned a full capture of the site from October 2022 — a polished, professional-looking CFD and crypto trading platform, complete with a "How does it work?" explainer on contracts for difference, a "Join Us" call to action, and a live-updating ticker of cryptocurrency prices running along the bottom of the page. Nothing about the archived site itself would have obviously flagged it as fraudulent to a prospective investor.

Wayback Machine archived capture of the RSI-Platform website home page from October 2022, showing a How does it work? section on CFD trading and a live cryptocurrency price ticker
Figure 2. RSI-Platform Home Page (Wayback Machine capture, October 2022)

A WHOXY domain lookup on rsi-platform.io showed the domain had been registered on 23 June 2022 through the registrar NiceNic International Group Co., Limited, with the registrant's identity shielded behind a "redacted for privacy" WHOIS record. By the time this lookup was repeated in January 2026, the domain was no longer registered at all — an operating lifespan of well under two years, consistent with a scam site that is stood up, run until complaints accumulate, and then abandoned.

WHOXY domain search engine WHOIS lookup result for rsi-platform.io showing the domain is no longer registered, was last registered 23 June 2022 through NiceNic International Group Co. Limited, with the registrant redacted for privacy
Figure 3. WHOXY Domain Search Engine — rsi-platform.io WHOIS History

Names and contact information findings. Running the list of SA phone numbers through Truecaller produced mixed results: some numbers resolved to named individuals, others returned nothing at all, and — most tellingly — one single number returned a different name on separate lookups performed weeks apart. That kind of instability is a strong signal of a VoIP or reassigned SIM number being recycled across an operation rather than belonging to one consistent individual.

Evidence Enrichment and Processing

Domain name findings. BigDomainData and the registrar's own NiceNic hosting records were cross-referenced to identify other domains sharing the same hosting infrastructure as rsi-platform.io — several of which carried their own history of scam-related complaints once checked. Crypto payment addresses recovered from the archived site's footer and supporting pages were checked against the VALR payment-routing detail already established in the earlier on-chain paper, reinforcing the link between the website itself and the funds the victim had transferred.

Names and contact information findings. Maltego transforms run against the phone numbers and alias names surfaced further connections to HelloPeter and Trustpilot complaints referencing the same names, and to a company named Vestro Group LTD, which appeared in the platform's consumer-facing complaint trail but could not be verified as a registered entity in Seychelles, its claimed jurisdiction. IntelTechniques and Breach Directory searches against the website's contact email returned no verified breach records. An XDS credit-bureau check and a CRDB porting-history check on the flagged phone number revealed it had been ported across at least three differently registered names within a short window — read alongside the earlier Truecaller inconsistency, this is a strong indicator of an organised, syndicated operation deliberately cycling SIMs and identities rather than a single individual acting alone. WhatsApp chat logs already retrieved during the earlier on-chain investigation were re-examined specifically for off-hand personal detail leaks.

"Mr-X" findings. A distinctive alias surfaced repeatedly across the WhatsApp chats and the consumer complaint sites, prompting a dedicated sub-investigation the authors refer to throughout as "Mr-X." WhatsMyName was used to check the alias's presence across dozens of other platforms; a Pinterest account under a closely matching handle was located; a YouTube reverse-image search against a profile photo associated with the alias returned partial visual matches; targeted Google Dorking against distinctive phrasing lifted from the chat logs surfaced a small number of forum posts using the same language; and a LinkedIn profile carrying a plausible real name was found matching some, but not all, of the details gathered so far.

Theory Development and Validation

Three competing theories were developed and tested against the accumulated evidence:

Theory 1 — Mr-X is a victim. Considered first, given how often scam operations themselves recruit unwitting victims as money mules or intermediaries. Ultimately set aside: Mr-X's apparent level of platform-specific knowledge, the timing of his messages relative to the victim's transfers, and his apparent role in directing certain fund movements were not consistent with someone who was simply another defrauded party.

Theory 2 — Mr-X worked with or for RSI-Platform directly. Investigated in some depth, but ultimately refuted. His apparent physical location, financial circumstances, and the specific accounts and platforms he was actually linked to did not line up with him being an active operator of the scheme — the evidence connecting him to RSI-Platform's operational side was circumstantial and did not hold up once tested.

Theory 3 — Mr-X used the platform, or a connected identity, to hide money from his ex-wife. This is the paper's currently predominant theory, though not yet conclusively proven. It would explain why Mr-X's digital footprint overlaps with RSI-Platform's financial and technical infrastructure without him necessarily being one of its operators — he may simply have used the same rails, for entirely separate personal reasons, at the same time the platform was defrauding other victims.

None of the three theories is dismissed lightly here — each was tested against the specific evidence gathered, and the paper is explicit that Theory 3 is "currently predominant" rather than confirmed. Off-chain OSINT enrichment narrowed the field from three plausible explanations to one leading candidate, but stopped short of definitive proof.

Suspect Identification and Reasonable Grounds

Two findings were flagged as providing reasonable grounds for further formal action. First, the phone-number porting anomaly — one number, three different registered names in a short window — is difficult to explain innocently and points toward deliberate identity-cycling. Second, the domain's registration itself shows hallmarks of a deliberately obscured scam operation: privacy-shielded WHOIS records, a short operating lifespan, and shared hosting infrastructure with other flagged domains, none of which is consistent with a legitimate financial services business. Kyrrex.com, already implicated as a downstream destination in the earlier on-chain paper, was identified as the most promising next subpoena target, sitting at a point in the fund flow where exchange-held KYC records could plausibly connect the pseudonymous on-chain trail to a real identity.

Law Enforcement Function

The paper recommends two concrete next steps for the investigating authority: a formal subpoena to Kyrrex.com for account-holder KYC records tied to the addresses already identified, and a request to the domain registrar NiceNic International Group Co., Limited for any underlying registrant records held behind the privacy-shielded WHOIS entry. Several unknowns remain open at the time of writing — the true identity of RSI-Platform's operator or operators, whether Mr-X has any deliberate role in the scheme at all, and whether the operation is the work of a single actor or a coordinated syndicate spanning South Africa and the United Kingdom.

Link Analysis

The full off-chain link analysis, built in Maltego, maps everything gathered across both enrichment passes around a single central "Suspect" node: the flagged phone numbers, each tagged with its mobile provider (Vodacom, MTN, Telkom Mobile, Hutchison Mobile) or VOIP line; the messaging platforms used to make contact (WhatsApp, Telegram, Snapchat); the scammer alias names surfaced through Truecaller and XDS; a Bitcoin address linked via the VALR payment-routing detail; and the rsi-platform.io domain itself, connected outward to its registrar (NiceNic International Group Co., Limited), its website footer contact email, its consumer complaint trail on HelloPeter and Trustpilot, the unverifiable Vestro Group LTD entity, and a cluster of localised South African victims.

Maltego link analysis graph centred on a Suspect node connected to multiple phone numbers with mobile providers, messaging apps, scammer alias names, a Bitcoin address, and the rsi-platform.io domain linking outward to its registrar, payment routing, website footer, consumer complaints and localised victims
Figure 4. Link Analysis

Conclusion

Returning to this paper's two objectives: on the first, whether a disciplined, iterative OSINT enrichment cycle can meaningfully extend an investigation once on-chain tracing has plateaued — the answer is yes. Applying the Evidence Overview, Evidence Enrichment and Theory Development cycle to fragments as ordinary as a domain name, a handful of phone numbers and a scattering of alias names produced a substantial, structured suspect network where the on-chain trail alone had stalled at an exchange boundary. On the second objective, whether this specific case could be resolved to a named, identified human operator — not yet. Mr-X's exact role remains unresolved, with the "hiding money from his ex-wife" theory currently the most consistent with the evidence gathered, but unproven.

The case also illustrates just how difficult transnational cryptocurrency investment scams are to pursue to a conclusion: a UK-registered address, an entity claiming Seychelles registration that cannot be verified, South African victims, a mix of local and international phone numbers and VOIP lines, and an offshore domain registrar together span at least three jurisdictions, none of which can act alone. What this paper does show is that combining structured on-chain analysis with an equally structured, iterative off-chain OSINT process gives investigators a genuinely better chance of eventually closing that gap — even when, as here, full identification isn't achieved on the first pass.

Loading ratings…
Found this useful? Rate this post:
Thanks for rating!

Comments (0)

Loading comments…

Leave a comment

Your email address will not be published. Comments are reviewed before appearing publicly.