Bitcoin Forum
July 24, 2026, 02:37:59 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Warning: Suspicious CEX Trading Bot Shows Malware Behavior (apip2p.top Domain)  (Read 180 times)
albon (OP)
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
June 09, 2026, 02:56:59 PM
Merited by hugeblack (2), The Cryptovator (2), JeromeTash (2), eaLiTy (1), Charles-Tim (1)
 #1

What happened:: I found a service offered by this user related to a CEX trading bot in the Services section. To verify whether this software was safe for forum users, and because this user has promoted this unknown bot service more than once, I contacted the bot developer through their official email address, hello@apip2p[.]top, and asked for a trial version so I could test it myself.

The developer replied to my email and later contacted me on Telegram.



Through Telegram, they sent me a file named Trial.zip, Inside the archive was a folder named App/.



The executable file is P2P_USDT_Bidding.exe, with a size of 42.17 MB.

- config.json (for Binance)
- okx_config.json (for OKX)
- bybit_config.json (for Bybit)

The software appears to target exchange credentials, including API keys, passwords, and active login sessions.

Trial.zip | 2/67 security vendors flagged this file as malicious | contains-pe | detect-debug-environment | long-sleeps | Detected as W32.Malware.B20A38B0 by Bkav Pro and Trojan.Win64.Silverfox.me by Kaspersky. VirusTotal also associates the archive with the SilverFox trojan family and categorizes it as a trojan. Matches rule *Potential Vcruntime140 DLL Sideloading* by Swachchhanda Shrawan Poudel (Nextron Systems) in the Sigma Integrated Rule Set (GitHub).



SHA-256: 0f4e0b7af220b62d493fc732526aa795b81ffb63184d35ca95460ea07030bfdc

VirusTotal:
https://www.virustotal.com/gui/file/0f4e0b7af220b62d493fc732526aa795b81ffb63184d35ca95460ea07030bfdc/

---

P2P_USDT_Bidding.exe | 4/70 security vendors flagged this file as malicious | 64-bit overlay | Detected by multiple security vendors, including Kaspersky (Trojan.Win64.Silverfox.me), CrowdStrike Falcon (Win/malicious_confidence_90% (D)), SecureAge (Malicious), and Bkav Pro (W32.Malware.B20A38B0). VirusTotal also associates the file with the SilverFox trojan family and categorizes it as a trojan. Matches rule *PyInstaller* from ruleset PyInstaller at https://github.com/bartblaze/Yara-rules by @bartblaze.





SHA-256: a288b5e9c8bc92911c6c0fd0c6f851e22e51305d1df24563dbe1bb4610d18137

VirusTotal:
https://www.virustotal.com/gui/file/a288b5e9c8bc92911c6c0fd0c6f851e22e51305d1df24563dbe1bb4610d18137

From what I found, this is a closed-source trading application distributed privately through Telegram. Several security warnings were raised during the analysis, suspicious behavior, and features that interact with exchange credentials make it difficult to trust with exchange accounts, API keys, or other account credentials.

Developer Profile Link: https://bitcointalk.org/index.php?action=profile;u=3738952

Reference Link:

[1] Binance P2P Auto Transfer Bot: Auto Transfer, Auto Bill Check, and Auto Order
[2] Binance/Bybit P2P Bot
[3] Apip2p[.]top | WHOIS

Domain registration details:

Quote
Domain: apip2p.top
Registered On: 2025-12-09
Expires On: 2026-12-09
Updated On: 2025-12-09
Registrar: NameSilo,LLC
Abuse Email: abuse@namesilo.com

PM/Chat Logs: https://www.talkimg.com/album/XzAG




Additional Notes: I advise against interacting with this developer or their bot, as it is closed-source and the domain is very new with no verified clients or reviews. There are signs it may be high-risk. Be careful.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
albon (OP)
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
June 10, 2026, 11:54:44 PM
 #2

Update:

A report has been submitted to the domain registrar NameSilo abuse@namesilo[.]com with the necessary evidence requesting the takedown of this domain, which is being used to distribute a suspicious CEX trading bot that shows malware-like behavior. The report is currently under review, and we are awaiting their decision.

Also, I have opened a support ticket with MetaMask under ticket #256284 to report this domain so that a warning message can be displayed, helping to prevent potential victims.

I have also reported and blocked @eason01993 on Telegram, and I will submit a report to -> @notoscam as well, in hopes that they will mark this account as a SCAM.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
JeromeTash
Legendary
*
Offline

Activity: 2954
Merit: 1579


Heisenberg


View Profile
June 11, 2026, 12:44:53 PM
 #3

Thanks for the investigations and reporting the findings here. I don't know if the member has been banned, but quite a number of his posts have been deleted except one. I have seen a few members advertise suspicious trading bots around the forum, and you get to wonder why they do so instead of utilising the bot to make profits. It turns out that most of it is just malware.

They no longer share the links or files directly because they will get banned so fast but rather privately

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
albon (OP)
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
June 15, 2026, 01:38:36 PM
Last edit: June 15, 2026, 02:13:35 PM by albon
 #4

Thanks for the investigations and reporting the findings here. I don't know if the member has been banned, but quite a number of his posts have been deleted except one. I have seen a few members advertise suspicious trading bots around the forum, and you get to wonder why they do so instead of utilising the bot to make profits. It turns out that most of it is just malware.

They no longer share the links or files directly because they will get banned so fast but rather privately
I will also report his latest post. Thanks for your reply. I don’t think he’s been banned yet, but on the positive side is that the MetaMask team responded to my report about the domain and flagged it as potentially deceptive. This will make many people avoid visiting the domain, contacting the seller of this suspicious bot or purchasing it.



The reason people buy these bots is the features they are marketed with, which push them to purchase them despite the significant and potential risks that could lead to their devices being compromised and their CEX accounts being drained.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
craftyart1010
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 14, 2026, 07:14:47 PM
 #5

This is the same way SamFW scams happen. So if you mistakenly install this tool on your computer, you’re likely to get scammed. SamFW tools have hidden trojan droppers, and they can steal your seed phrases and wallet passwords. Then, if the scammer admin TungTata wants, they can inject a RAT into your computer. Everyone should be aware and not install anything on their computer. Any “free” software online may be a scam.

Here, tungtata distributes Trojan.Dropper through ‘Samfwfrptool’ and attempts to find victims.

https://bitcointalk.org/index.php?topic=5586649.msg66936860#new - Samfw.com Scam - Fraud & Trojan RAT Malware : SamFWTool Theft (XMR)

Separately, we have a CEX trading bot example, thanks to albon but they are looking for more victims.
craftyart1010
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 18, 2026, 10:56:50 AM
Last edit: July 18, 2026, 11:11:19 AM by craftyart1010
 #6

https://www.msn.com/en-us/news/crime/florida-man-arrested-after-stealing-220000-in-crypto-using-malware-hidden-in-steam-games/ar-AA288IeL

Same scam pattern has also been used by SamFW. Tungtata, a Vietnamese scammer, advertises on the internet that his ‘tool’ can remove FRP and other issues, but what it actually does is install malware on the victim’s computer. A similar scam has also been reported in MSN News, where malware is being installed through games. Tungtata did the same thing to his SamFW tool as well.

Another example of the same scheme is cryptocurrency trading bots contain malware and follow the same scam patterns.

Social engineering via a fake “legit tool”: attacker markets a “one-click” FRP removal / support tool (or trading bot / game-related download) to earn trust and drive downloads.

once installed, the malware targets the victim’s crypto wallet(s)/browser data and can watch for wallet activity.

FRP tools, trading bots, or even “games on Steam” are just different packaging/delivery lures the underlying pattern is malware distribution

albon (OP)
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
July 20, 2026, 02:01:34 PM
 #7

Another example of the same scheme is cryptocurrency trading bots contain malware and follow the same scam patterns.

Social engineering via a fake “legit tool”: attacker markets a “one-click” FRP removal / support tool (or trading bot / game-related download) to earn trust and drive downloads.

once installed, the malware targets the victim’s crypto wallet(s)/browser data and can watch for wallet activity.

FRP tools, trading bots, or even “games on Steam” are just different packaging/delivery lures the underlying pattern is malware distribution
Many people are attracted to the features of a fake tool and forget the security precautions before using it or even the consequences if the tool contains a Trojan or other malware. Some users trust a tool just because of positive feedback, someone on YouTube recommending it, or a paid article. They don't check the tool, use it in an isolated environment, or even run it on a computer that does not contain important data. In most cases, their blind trust may lead them to lose their crypto  and data in the blink of an eye.

Unfortunately, there are already many victims and plenty of stories showing the risks of downloading unknown tools. Yet many people still take the risk. Some tools even use delayed execution to avoid detection by security software, So everyone should be careful before downloading or installing any software.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
The Cryptovator
Legendary
*
Offline

Activity: 2968
Merit: 2598


Protect your privacy 🔏 it's very important


View Profile WWW
July 20, 2026, 03:23:42 PM
 #8

Many people are attracted to the features of a fake tool and forget the security precautions before using it or even the consequences if the tool contains a Trojan or other malware. Some users trust a tool just because of positive feedback, someone on YouTube recommending it, or a paid article. They don't check the tool, use it in an isolated environment, or even run it on a computer that does not contain important data. In most cases, their blind trust may lead them to lose their crypto  and data in the blink of an eye.
Because we are too greedy, when we find something interesting that would possibly make money easily, we jump on that. Unfortunately, when we realize that it's a scam, then it's already too late. We can't recover lost funds since crypto is an irreversible currency. Trust me, a lot of victims don't even search for feedback, although online feedback is easy to manipulate. They dreamed of becoming quick rich as they fell into a trap.

Unfortunately, there are already many victims and plenty of stories showing the risks of downloading unknown tools. Yet many people still take the risk. Some tools even use delayed execution to avoid detection by security software, So everyone should be careful before downloading or installing any software.
As I wrote above, it's all about greed. We have to trust first; there is no easy money-making software or tools. Otherwise developers themselves would become billionaires through their tools.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
OcTradism
Legendary
*
Offline

Activity: 2548
Merit: 1029



View Profile
July 20, 2026, 03:31:09 PM
 #9

Because we are too greedy, when we find something interesting that would possibly make money easily, we jump on that. Unfortunately, when we realize that it's a scam, then it's already too late. We can't recover lost funds since crypto is an irreversible currency. Trust me, a lot of victims don't even search for feedback, although online feedback is easy to manipulate. They dreamed of becoming quick rich as they fell into a trap.
Scams mostly start with things related to money, opportunities of getting money easily, and to sum up, they are more attractive with people if they are too good to be true offers.

With this most common thing in scam offers, people only need to know the fact like "too good to be true offers" are most favorite scam tool used by scammers, they will not be scammed with such. People who are newbies, don't know about it, can be scammed and it's acceptable but if people knew about it, but did not control their greediness well enough, and were scammed, it's unacceptable.

Cryptocurrency scambook.
Quote
How to protect yourself
Don’t be delusional. If something’s too good to be true, it probably is.

craftyart1010
Jr. Member
*
Offline

Activity: 34
Merit: 1


View Profile
July 21, 2026, 09:26:51 AM
 #10

Another example of the same scheme is cryptocurrency trading bots contain malware and follow the same scam patterns.

Social engineering via a fake “legit tool”: attacker markets a “one-click” FRP removal / support tool (or trading bot / game-related download) to earn trust and drive downloads.

once installed, the malware targets the victim’s crypto wallet(s)/browser data and can watch for wallet activity.

FRP tools, trading bots, or even “games on Steam” are just different packaging/delivery lures the underlying pattern is malware distribution
Many people are attracted to the features of a fake tool and forget the security precautions before using it or even the consequences if the tool contains a Trojan or other malware. Some users trust a tool just because of positive feedback, someone on YouTube recommending it, or a paid article. They don't check the tool, use it in an isolated environment, or even run it on a computer that does not contain important data. In most cases, their blind trust may lead them to lose their crypto  and data in the blink of an eye.

Unfortunately, there are already many victims and plenty of stories showing the risks of downloading unknown tools. Yet many people still take the risk. Some tools even use delayed execution to avoid detection by security software, So everyone should be careful before downloading or installing any software.

We’re all human and we can make mistakes. Recently, I’ve seen malware distributed through legitimate tools and real-looking softwarex like Steam games, trading bots, and in my case, FRP tools (for example, the Samfw scam).  

Even articles that are paid or promotional sometimes criticize the Samfw scam as if it’s completely harmless claiming there’s no malware and that everything is safe. Also, the Samfw tool doesn’t work in sandbox environments or in VirtualBox, which was a biggest red flag but sorry to me i didn't get it. Do not download, install, or run any software from samfw.com!

https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/

check this out albon similar scam with samfw.
albon (OP)
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
July 21, 2026, 01:31:25 PM
 #11

With this most common thing in scam offers, people only need to know the fact like "too good to be true offers" are most favorite scam tool used by scammers, they will not be scammed with such. People who are newbies, don't know about it, can be scammed and it's acceptable but if people knew about it, but did not control their greediness well enough, and were scammed, it's unacceptable.
Greed is one of the reasons people get scammed, but it's not the whole story. Scammers also create software that claims to help people solve their problems, so many users download these tools and believe the scammers' claims hoping to solve their problem, only to end up falling into the trap.

We've seen this many times, even during the recent FIFA World Cup, where malware was distributed through software claiming to provide free access to football channels. We've also seen many other tools claiming to help users recover crypto wallets or offering trading and AI software with advanced features. So people should check a tool's reputation, make sure it comes from a trusted source and check it carefully before running it.

Even articles that are paid or promotional sometimes criticize the Samfw scam as if it’s completely harmless claiming there’s no malware and that everything is safe. Also, the Samfw tool doesn’t work in sandbox environments or in VirtualBox, which was a biggest red flag but sorry to me i didn't get it. Do not download, install, or run any software from samfw.com!
That's why I always tell people to be cautious of paid or promotional articles about tools and software. A lot of them just copy what the developer says and publish it just to make money without even checking if it's true. They only care about making money without caring if their readers get harmed.

I believe you'll find hundreds of other warning articles about similar malicious tools.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!