HUMAN’s Satori Threat Intelligence Team recently exposed FunFoneFarm, an off-the-shelf ecosystem that uses phone farms, orchestration software, and an AI control layer to make scams (like romance scams, pig butchering, and investment fraud) easier and cheaper for threat actors to run. In order to truly understand the underlying economy that underpins these scams, however, we needed to get our hands dirty and become victims ourselves to further our investigation.
So instead of blocking suspicious outreach, we set up controlled environments and burner profiles, essentially rolling out the welcome mat. We became the perfect “victims” so we could reverse engineer their operations from the inside out. From there, we were able to watch the scam lifecycle unfold:
1. The Dating App Funnel: We set up profiles meant to look like the ideal mark, signaling a bit of wealth, a stable career, loneliness, age, and an interest in making a serious connection. Scammers are always on the lookout for people with disposable income and emotional vulnerability. Not surprisingly, accounts using stolen and AI-generated photos swarmed almost immediately.
2. The Conversation Engine: We witnessed firsthand how phone farm orchestration software and AI allowed a single operator to manage hundreds of simultaneous conversations. Their scripts were highly polished and designed to quickly move us off the initial app and onto encrypted messaging (like Telegram or WhatsApp) to evade platform detection.
3. Following the Money: The ultimate goal is always extraction of money. After simulating the weeks of “grooming” required to build trust, we watched the pivot happen in real-time. Casual romance chatter seamlessly transitioned into high-pressure investment advice, directing our personas toward fraudulent cryptocurrency platforms.
Ultimately, through this engagement, Satori was able to more effectively understand exactly how real scammers used these phone farms to target victims and how to better detect this behavior at a technical level. In addition to fully mapping the lifecycle of the threat, becoming victims ourselves was a huge asset to our investigation:
We don’t stop at identifying suspicious infrastructure or documenting known tactics. By engaging with threats in controlled environments, we see how fraud actually unfolds, find the pivots and signals that static analysis misses and turn those insights into better detection and disruptions. Want to see exactly how these scams operate once you’re on the hook? Read the full Satori Threat Intelligence breakdown of the FunFoneFarm economy or attend our webinar digging into the threat.
