Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actioncryptocurrency-platform-riskcybercrime-service-ecosystem

US Crackdown on Southeast Asian Crypto Scam Networks and Prince Group Forfeiture

Updated 3mo agoFirst seen Nov 12, 20252 sources

The U.S. Department of Justice, in collaboration with federal law enforcement and interagency partners, has intensified efforts to combat large-scale cryptocurrency-enabled fraud originating from Southeast Asia. This includes the creation of the Scam Center Strike Force, which targets scam compounds that use forced labor to perpetrate investment fraud, and the designation of groups such as the Democratic Karen Benevolent Army (DKBA) and companies like Trans Asia and Troth Star for their roles in these operations. The U.S. government estimates that Americans lost at least $10 billion to such scams in 2024, a significant increase from previous years, and has already seized over $401 million in cryptocurrency assets, with further forfeiture actions underway.

A notable case in this crackdown involves the Prince Group, led by Chen Zhi, which operated forced-labor scam compounds in Cambodia. The U.S. Department of Justice unsealed an indictment against Chen Zhi for wire fraud and money laundering, and filed a civil forfeiture complaint for approximately 127,271 Bitcoin—proceeds from these illicit activities. The Chinese National Computer Virus Emergency Response Center (CVERC) has alleged that the U.S. may have acquired these bitcoins from a 2020 attack on the LuBian bitcoin mining pool, raising geopolitical tensions. The Prince Group action is seen as a landmark in the ongoing U.S. campaign to disrupt the infrastructure behind Southeast Asian pig butchering scams and related cybercrime.

Share:
US Crackdown on Southeast Asian Crypto Scam Networks and Prince Group Forfeiture
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Nov 13, 20257mo ago

US rejects Chinese allegations over LuBian mining pool bitcoin seizure

US officials dismissed China's accusation that the US conducted an extensive hack of the LuBian mining pool, disputing the claim that the bitcoin was improperly acquired through cyber intrusion. This official rebuttal was reported the following day.

Nov 12, 20257mo ago

China-linked CERT accuses US of hacking LuBian mining pool and stealing bitcoin

Chinese authorities, through the National Computer Virus Emergency Response Center, publicly alleged that the US hacked the LuBian cryptocurrency mining pool and obtained bitcoin connected to scam proceeds. The accusation appears to have become public by mid-November 2025 and is the core event described across both references.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

US Crackdown on Southeast Asian Crypto Scam Networks and Prince Group Forfeiture | Mallory