Foreign Agents in Asia Target Americans on Facebook
(Part 1 first published in our newsletter on 12/3/25 and Part 2 on 12/17/25; updated below on 1/14/26)
The article below is the conclusion of more than 100 hours of investigation into various Facebook Groups and Posts made between mid-October and early December, 2025. Based on my findings, I firmly believe that my investigation has produced a significant amount of evidence showing that agents (cybercriminals) from Asian countries, primarily Vietnam, are making a daily, coordinated and significant effort to target Americans with malicious clickbait, primarily on Facebook. Amongst the findings of my investigation, below you’ll find a growing list of both suspicious, or confirmed malicious websites posted as links on Facebook, AND the suspicious Facebook Groups whose Admins are responsible for these posts. On January 14, we also published a Newsletter Top Story that clearly shows cybercriminals primarily located in Nigeria targeting fans of Taylor Swift & Traves Kelce on Facebook as well. This revelation is important because it suggests that all of these cybercriminals are hired by a bigger fish who is funding and driving this attack on Americans. We think we know who it is, but have very little evidence to support our suspicions… at this point.
On Tuesday, November 18, I saw a November 9 post on my Facebook feed saying that the famous 98-year old actor, Dick Van Dyke, was suing Pete Hegseth, the US Secretary of Defense, for $60 Million Dollars! (As of 12/27/26, this post has been removed.) This particular post had over 1800 emoji reactions, more than 200 comments and was shared over 180 times. But this post was not true! It was written by someone who displayed a modified American Flag for their profile and their account name was “Ghanshyam yadav” from Nepal. (Notice their capitalization error. This account has also been removed from Facebook as of 12/27/25.) His account had more than 19,000 followers. But worse than a lie, I believe that the link included with this story was malicious clickbait. Ghanshyam’s post included a link to a ‘Hollywood article’ on a website called hollywoodbuzzdaily[.]space. This domain was registered less than 4 weeks earlier, through a proxy service to hide the real domain owner. This domain was found to be malicoius on VirusTotal.com. When I checked the top page of this website (safely) on November 18, and again a week later, there was NO content at all on this website. This strongly suggests that the entire site is a fraud and created as a landmine to target Americans on Facebook. After nearly 100 hours of investigation, this landmine is just one of hundreds I discovered on Facebook, and as recently as December 27! I was curious whether or not this exact malicious clickbait had been posted to other Facebook Groups and Googled it. That is how I discovered hundreds of other malicious and suspicious posts. For example, my searches of this Dick Van Dyke post turned up 348 Facebook Group posts made in the last year. (Most had been made in from August through the start of December .) About 60% of these posts included a suspicious link and 28% (98) of these links were confirmed as malicious. Some posts led to other suspicious posts. The most popular clickbait topics included lawsuits against Pete Hegseth and posts about Keanu Reeves saving dogs. Given the many common threads that these hundreds of suspicious/malicious posts had in common, I wondered who might be responsible for them. Further investigation turned up unexpected clues as to the possible country where these cybercriminals may be located! After reading this story, I guarantee you won’t look at a Facebook post in the same way!
The disinformation campaigns I uncovered in hundreds of social media posts turn out to be much more widespread than I thought. There have been hundreds of posts on Facebook, Instagram and LinkedIn, recently claiming to be a celebrity who is suing Pete Hegseth and Network for $60 Million dollars. These posts have reached tens of thousands of people. In most of the posts I found, there was a link pointing to a suspicious website that, supposedly, broke the story. Here are a few of those examples. DO NOT click the link if you visit these Facebook posts!
- Oct. 19 Facebook post: Robert Irwin sues Pete Hegseth and Network for $60 Million… (Shared nearly 5000 times and has over 7700 comments!) The link points to colofandom[.]com, which was registered on 9/11/2024 using Namecheap in Iceland. (Namecheap is a favorite Registrar by cybercriminals!) Scam-Detector rates colofandom[.]com as “doubtful, medium-risk alert.”
- Facebook post on 11/15/25: Dick Van Dyke slaps Pete Hegseth and Network with $60 Million… The link in this post points to the domain zwent[.]net, which was registered on 8/15/2025 using Namecheap in Iceland. By 12/1/2025 this Facebook group and its post have been removed from Facebook! Scam-Detector scores this zwent[.]net as “untrustworthy, risky, a danger.”
- Facebook post on 11/10/25: Jelly Roll sues Pete Hegseth and Network for $60 Million… I was unable to find any link following this post. By 12/1/2025 this Facebook group and its post have been removed!
- Facebook post on 10/20/25: André Rieu sues Pete Hegseth and Network for $60 Million… The link points to freshhaynews[.]com, which was registered on 7/13/25 using Namecheap. Scam-Detector scores this website as “suspicious, unsafe & doubtful.”
- Finally, I used the “site:” command to search all of Facebook for these posts and found hundreds of hoax posts! These posts make false claims about many people suing Pete Hegseth, including Dolly Parton, Jelly Roll, Rachel Maddow, Neil Diamond, Bob Seger, Carlos Santana, Barbra Streisand, Bruce Springsteen, Neil Young, Tiger Woods, Jimmy Page, Mick Jagger, Jimmy Kimmel, Johnny Mathis, Pink, and many more well-known people. Many of these posts include links to suspicious “news” websites.
In October, Yahoo News published an article that details some of these fake posts across Facebook. In each post, some famous person is suing Pete Hegseth and Network for $60 Million dollars. Once again, it is critically important not to believe what you read and see in social media until you can verify it through credible sources! Sadly, Information online, especially in social media, can no longer be trusted. But this is not the end of this deluge of malicious clickbait. While investigating these lies, I came across other lies that were also spreading on social media, especially Facebook. Once again, most posts included a very suspicious, or a confirmed malicious link to a newly registered website. Here’s another example, that begins with a quote all in caps… “ALLERGIC TO HONESTY?” A celebrity name follows, such as Rachel Maddow, and then “…Destroys Karoline Leavitt on Live TV with One Cold-Blooded Line That Left the Studio Frozen and the Internet in Flames!…” This particular example includes a link to the “full story” at a website called livenews24h[.]com. But this website was recently registered on 7/20/2025 through Namecheap in Iceland and was found to be suspicious on VirusTotal.com and Scam-Detector.com rates this website as “suspicious, unsafe, and doubtful.”

The above post included a supposed quote from Ms. Maddow saying “If truth sounds like propaganda to you, maybe you’re just allergic to honesty”. I asked Google to search for this exact quote and was surprised to find it listed more than 100 times, attributed to many different people on various social media sites, but especially on Facebook! And many of these posts included a suspicious/malicious link to an oddball website!
Below are three more examples of these suspicious posts, along with the website links they included. These quotes were attributed to Rachel Maddow, Andrea Bocelli, and Mike Tomlin. The domains used in the links to supposed “news” websites about these stories include one found as malicious by VirusTotal.com, and one found as suspicious…
- Shuihar[.]info – registered on 11/6/2025, just 2 weeks before this post was made on Facebook; I discovered 3 other fake posts that contained links to this website. A security service on VirusTotal shows this domain as suspicious and Scam-Detector.com rates this website as “untrustworthy, risky, a danger.”
- Sportylife[.]blog – registered on 10/9/2025 using a proxy service to hide the owner’s identity, just over 4 weeks before this post appeared on Facebook; VirusTotal.com shows this domain as a phishing fraud.
- NFLinsight360[.]com – registered on 7/27/2025 by someone in Vilnius, Lithuania; NFLInsight360[.]com claims to be an independent sports media platform providing comprehensive NFL coverage including “news, analysis, and insights, aiming to build a community for fans.” Scam-Detector.com rates this websites as “suspicious, unsafe, doubtful.” It took us less than a minute to easily identity an article posted on this website on November 21 by “binbin” as a lie. The article headline says “BREAKING – ABC News Anchor Suspended After Jason Kelce Exposes His Private Comment” and included a photo of the former ABC News journalist, Terry Moran. However, Terry Moran was fired from ABC News in June of this year after making a post on X about Donald Trump that ABC said violated their journalist policies. NOTHING about his suspension, and subsequent firing, had anything to do with Jason Kelce. (Many sources, including: AP News) While investigating this lie posted on NFLinsight360[.]com, I also found two more Facebook posts saying the same thing. But the first, made on November 23, claimed it was Coach Ryan Day who exposed Moran’s comment. The second post, made on November 24, claimed it was Deion Sanders who exposed Moran’s comment. This second post included a link to another very suspicious website called lumaflow[.]blog. This domain was registered about 6 weeks earlier on 10/13/2025 and VirusTotal shows a security service identifying this domain as malicious.
After investigating hundreds of these posts during two weeks in November, it became crystal clear that foreign actors are behind the use of this patently false and suspicious/malicious content. I’ve found a number of common threads underlying these many various Facebook posts. This effort leads me to suspect that this is a huge disinformation campaign meant to weaponize Facebook for targeting Americans. In addition to building media distrust by Americans, VirusTotal.com reveals that there is malicious intent behind many of the websites linked to these posts. Also during my two week investigation I learned that this threat is dynamic and changing. More than a half dozen of these links were not initially identified as suspicious or malicious on VirusTotal. However, days later they were found to be malicious. A few Facebook posts and groups have been taken down a week later, no doubt for violating their policies. Also, a few of these malicious domains have been terminated and had their content removed since my investigation began.
What do these suspicious & malicious posts/links have in common?
- Lots of these questionable links have the same type of coding structure. E.g. after the domain name, many of the links point to a directory called “posts.” This is odd because these many dozens of websites have different domain names, were registered at different times through different Registrars, and were related to different news stories. It is no coincidence that their top directory is called “posts.” It informs us that the same criminal gang is likely behind all of these threats and is re-using the same website template for many of these “news” sites.
- I also found a few suspicious links that included a folder that used a Vietnamese name.
- I discovered that five of the 89 domain names I identified were registered by someone from Vietnam named Quang Nam. Out of 89 domains, a total of 12 (13%) had some connection or reference to Vietnam.
- In total, my initial November investigation uncovered 89 suspicious domains used in bogus Facebook posts. Of these 89, VirusTotal informed me that 40 (45%) of these domains were identified as malicious and another 10 (11%) were identified as suspicious. However, since many of these suspicious/malicious domains were posted multiple times on many Facebook Groups, I collectively found them 184 times across the 348 links Google found on Facebook from my searches. This number represented 53% of all posts I investigated at that time.
- Many times I carefully explored these suspicious websites, took screenshots of their pages, and found that most of these sites claimed to be some type of “news” website. But these “news” services lacked any credibility. They didn’t include any phone numbers, addresses, or information about their news organization, as you would expect credible services to provide. Below is a screenshot showing some of the content from three of these supposed “news” websites. I noticed that many of the articles heavily focused on American politics and/or American culture.
On a few ocassions I also discovered that a link to a “news” website about a story in a Facebook post was not found to be suspicious or malicious. HOWEVER, that link then redirected your click to a different “news” website that WAS FOUND to be suspicious or malicious. Here are two examples that Sucuri.net found to redirect your click to malicious websites, as identified by VirusTotal…
- A link to “echobeat[.]blog” redirects to a malicious website called livextop[.]com
- A link to “fcaroyal[.]site” redirects to a malicious website called topnewsource[.]com
As I was about to discover, these bogus posts have reached hundreds of thousands of Americans, and possibly more. They have triggered tens of thousands of comments, emoji responses and shares. Occasionally, I see that some people have identified these posts as lies, misinformation or disinformation campaigns, as the screenshot below shows. But I found these realizations very small in number…
It has become exceptionally clear that bad actors from other countries are using social media websites, especially Facebook, as a means to attack and divide Americans again! Many of these posts appear to be from very Pro-American accounts or groups, or from accounts using American symbols. For example, I saw several Facebook groups, like this one, that seemed very sketchy. It is called “America in Focus” with 33,000 followers. This Facebook Group has odd posts on it, and appears to be associated with another suspicious “news” site called autulu[.]com. For instance, several of these sketchy posts I saw on November 25 start with these sentences…
- My Parents SKIPPED My Wedding For My Sister’s Engagement—So I Married At My $7M Malibu Estate
- When I Got Engaged, I Quietly Kept My $1.2 Million Estate to Myself—Just In Case. Two Days After My Wedding, I Learned Why.
- My Parents Skipped My $15K Partnership Gala—So I Gave Their Seats to the People Who Earned Them
- My Husband Signed The Papers Grinning Ear To Ear. But When My Net Worth Was Shown, He… If you’ve ever been called a leech in your own home, this story is for you.
This suspicious Facebook group also shows its address incorrectly written as “65 Broadway, New York, New York, NY, United States, New York.” There was no apartment number or floor number provided for this New York street address either. They show their contact information as… (646) 791-5566, AmericaInFocus@gmail.com
Overwhelmingly, the content of the hundreds of posts I reviewed seemed to favor Anti-Trump Administration sentiment, as the example below demonstrates. I found this one on November 24, a week after it was posted by someone named Karley Weinberg. Karley’s profile photo shows the Statue of Liberty against an American flag in the background. But this “breaking news” story about Stephen Colbert is NOT TRUE! (DO NOT CLICK ANY LINKS in the Facebook post!) And yet, it had over 20,000 reactions, 3100 comments and 1700 shares! The post includes a link to the “fully story” on a website called madeafamily[.]com. This website was registered by someone in Pakistan less than three months earlier and VirusTotal shows this website to be a phishing scam!
Some of the bogus posts I found were not political at all but were focused on good deeds by famous people, such as Keanu Reeves or Jason Strathom. “In an act of bravery” these men were reported to have saved dogs in a flood zone. These posts included the misspelled phrase “sh0cked the nation.” (Zero is used instead of an “o”) In mid-November, I used the “site” command on Google to search Facebook.com for the exact incorrectly written phrase “sh0cked the nation” and found over 100 Facebook posts! Malicious/suspicious links were found on 42 posts of the 108 links to posts that Google returned. (5 links shown were duplicates, while 13 Facebook Groups had had their content removed and therefore unavailable to investigate. This means that 42 out of 90 available posts, or 47%, contained malicious/suspicious links!) (Note: On December 1, 2025, I ran the same Google search and Google returned more than 200 posts on Facebook that “sh0cked the nation.”
In an effort to bring more attention to these suspicious/malicious websites, I have listed all 89 of them below, at the bottom of this article, plus additional suspicious/malicious websites that I have found since November, 2025. I hope that this story forces you to seriously reconsider the authenticity of posts that you see on social media, especially Facebook. And, if you see a news link accompanying a post, DO NOT CLICK that link without further investigating it!
However, two very critical questions remain to be answered… Who are the agents behind these suspicious/malicious posts and where are they located? I believe part 2 of my investigation below addresses these questions….
EXAMPLES of FACEBOOK GROUPS WHERE SUSPICIOUS/MALICIOUS/FALSE POSTS ARE MADE BY THE GROUP’S ADMIN MEMBERS:
- Neil Diamond Fans (40.9K members as of 12/28/25) – On December 28, this group had 8 Admin members in charge of this Facebook Group. All 8 have foreign-sounding names and several of their accounts say they live in other countries, including 3 from Bangladesh, and 1 from Saudi Arabia. E.g. Manik Roy is an Admin and posted on 11/5 that “Neil Diamond Files $60 Million Lawsuit Against Pete Hegseth and Network Following Explosive On-Air Showdown.” This is a lie. The post included a link to a suspicious website called sheinee[.]shop. In late December, this website was found to be malicious (phishing) on VirusTotal.com. It has no top page and was registered on 9/23/25 using Namecheap in Iceland. (This is a favorite Registrar of cybercrminials.) Manik Roy has posted many times with links to this domain. Manik is a traditional Indian name. Jannat Eva is also an Admin of the Neil Diamond Fans FB Group. She also has many fake posts that include links to sheinee[.]shop e.g. 12 posts in less than 2 days; her profile is locked but says she lives in Bangladesh and has 247 friends. Interesting to note that Facebook says the Neil Diamond Fans group was created by someone named Fihima Khan. Fihima has a locked profile with 147 friends. No other information is available. The name Fihima is considered to be or Arabic/Muslim origin, commonly used in India and Asia. All Admin Members…
- Manik Roy – has posted suspicious links many times to this fan group, including 14 posts on December 27-28 that included links to a very suspicious website called teeturst[.]shop. This domain was registered less than 2 months ago on October 1 through Namecheap.
- Jose Vazquez – on 12/26/25, he posted multiple times and included a link to a suspicious domain called wealthtees[.]shop . This domain was registered 2 1/2 months earlier on 10/16/25 using Namecheap. In October, he made a post that included a link to a malicious website, as identified by VirusTotal, called paradoxfashion[.]shop. This malicious domain was registered a year earlier. He has posted many times and his posts include links to very suspicious, or malicious websites.
- Fihima Khan – posted many links in September, 2025 to a suspicious website called best-markets[.]shop. This website, registered in 2024, has been identified as malicious on VirusTotal.com.
- Forid Alm – In September, Forid also posted links on this fan group pointing back to the malicious website: best-markets[.]shop
- Tahmina Jannat – lives in Bangladesh and just joined this fan group as an Admin on 12/19/25
- Hanima Mis – just joined this fan group as an Admin on 12/26/25
- Jannat Eva – from Bangladesh, joined this fan group as an Admin on 8/6/25 and has made many posts that include suspicious links to teeturst[.]shop and sheinee[.]shop
- Md Atikur – from Bangladesh, is an Admin since 2024 to this group but shows no posts on his account
- Rock Soul Anthems (20K members as of 12/28/25) – On 10-13-25, Facebook Group Rock Soul Anthems made a post that included a suspicious link to pollywebart[.]com and stating another lie that began with “Bruce Springsteen sues Pete Hegseth and Network for $50 MILLION after shocking on-air attack.” Many other posts, including 1 on 12/28, also contain links to this suspicious website. The Rock Soul Anthem Facebook Group claims to be located at 869 N Cherry St, Tulare, CA 93274 and using phone number (559) 688-0821. But Google says that this is the phone and address for Adventist Health Tulare. The Rock Soul Anthems Facebook Group was created on 5/31/25 by a media agency in the U.S. but offers no verification; in fact, the account never completed a verification process. One of the Admin members lives in Vietnam.
- Watch Weekly (20K members as of 12/28/25) – this Facebook Group was created on 6/30/25 and FB informs us that the “Page Manager” and all 4 other Admins are located in Vietnam. Watch Weekly is supposedly a fan page for TV Shows and TV Channels. It has been called out by some FB members for posting lies. The “Author” of this group posts a lot of politically charged information, many of which include links to suspicious websites, such as starfocus360[.]com and breakingradar[.]com (Both were registered on 12/6/24 through Namecheap in Iceland.) Many of the links to these suspicious websites include a top directory that is using a traditional Vietnamese name such as thuuyenlt and ducthanht (duc thanh).
Foreign Agents Target Americans on Facebook – Part 2
(First published 12/17/2025)
As we head deeper into the holiday season, I have found more and more evidence on Facebook that foreign agents, most likely from Asia (e.g. Vietnam) are specifically targeting Americans with malicious intent. Circumstancial evidence suggests that some of this is a form of phishing fraud, while other evidence suggests that malware infections are also being used. But the end-game “why” is still not clear to me. I have enough evidence to be certain that this effort is massive, originating from other countries, and is clearly malicious and deceptive. And overwhelmingly, these attacks are weaponizing Facebook as the primary tool to reach people. In early December, TheDailyScam.com published part one of this story with many examples of this fraud. In part two of this report, I will dig more deeply into some of the individual Facebook accounts and Groups that I believe are heavily engaged in these targeted attacks. I also have some disturbing information about the frequency of these threats during the last few months. I urge you to share this information, as well as part 1 of this story, with your friends and family who use Facebook. Warning… As you read this article, if you choose to click and visit any of the many links I have included to Facebook Groups and accounts DO NOT click on any of the links or websites you may find in these individual Group posts or Facebook accounts.
As my investigations into the dozens of suspicious Facebook posts continued during the last couple of weeks, I wondered if these attacks against Americans were happening at the same rate, or at different rates over the past year or so. To evaluate this question I turned to Google. Using the “site” command, I asked Google to show us every time it found a post on Facebook that specifically contained a link to each of the four websites listed below. These four domains represented a small sample (4.5%) of the 89 suspicious/malicious websites I published in our first “part 1” article at TheDailyScam.com. I originally chose apkclass[.]info, for example, because it was alphabetically first on my list and had not been deemed malicious. But just one week after first evaluating it as a non-threatening site, VirusTotal changed their assessment and reported it as malicious! The other three websites shown below were selected because they were identified as very malicious by security services that reviewed them for VirusTotal…
- Apkclass[.]info – researched on 12/2/25, and found to be malicious by VirusTotal (Google found 374 links with this domain)
- Azontree[.]com – researched on 12/2/25 and found to be very malicious by VirusTotal, including malware; registered by someone in Lithuania (Google found 295 links with this domain)
- Quietfield[.]org – researched on 12/2/25 and found to be very malicious by VirusTotal; founded by someone from Vietnam (Google found 297 links with this domain)
- Usnews24today[.]com – researched on 12/3/25 and found to be malicious by VirusTotal; Sucuri.net found an anomaly on this website that might be malware. (Google found 110 links with this domain)
In total, Google found 1,076 malicious links to this small sampling of four websites posted across many different Facebook groups. That’s an average of 269 links per domain name. Multiply this average times the 89 suspicious/malicious websites I reported two weeks ago and you arrive at an estimated nearly 24,000 posts! (Since my initial research, I’ve discovered more than another half-dozen suspicious domains that I have not included in these numbers.) But more importantly, Google’s returns told us that most of these posts have occurred in the last four months, when compared to the preceding eight months. In other words, this data tells us that attacks against Americans on Facebook has significantly increased since the start of August. Below is a graph of this data. (NOTE: I believe that Google’s notification about how long ago a post was made on Facebook should be taken as an estimate only since I have no explanation from Google on how it arrives at it’s reported time stamps.)
After seeing evidence that these attacks were increasing, I began to investigate a handful of these Facebook Group creators and/or people who were posting these fabricated stories, or posting content containing suspicious links. (WARNING: If you choose to click any of the links below to these Facebook groups, admin/moderators, or accounts I have identified as suspicious/malicious, DO NOT click any links within their posts!)
We’ll start with Zerin Eriyan. Zerin Eriyan is a new moderator (starting on 11/4/2025) of a Facebook Group called Pink Floyd FAN Group, with 71K members. On November 15, she posted the following lie… “BREAKING: David Gilmour Stuns the World — Accepts “Best Vocal Performance” at the 2025 Grammys on Behalf of His Late Bandmate, Roger Waters” This statement is not true and easily refuted by a variety of Google searches. Zerin Eriyan’s Facebook account has only 34 friends, all of whom have very foreign sounding names, including two who post their names in the Bangla language, primarily spoken in India. Also, Zerin Eriyan uses a profile photo that Google has identified as a woman named Molly Stewart. (The profile photo used by Zerin Eriyan was posted by Molly Stewart in July, 2021 on her FB page. Molly’s photos can also be found on Molly’s TikTok page.) The name “Zerin” was unusual to me. I asked Google where it came from and Google identified it as a Persian name meaning “golden.” It is used by people from Iran, Afghanistan, Tajikistan, Egypt and other parts of central Asia. Zerin has posted many lies about Pink Floyd on her Facebook Group and many fans have called her out on this. Between November 5 and 25, for example, Zerin posted 17 comments to her FB Group. Several of these comments were written to suggest that a link for additional information was included in her first comment to her own post. But by December 5, no such links were found. The number of comments I found with these posts was less than the number of comments that Facebook indicated had been made. This suggested that Zerin’s first comment to these posts could have had a link included, but was later deleted or removed.
These many suspicious/malicious posts often use misinformation. On December 4 and 5, I conducted a very specific Google search on Facebook, using the “site” command again. This time I used the exact search words “sues Pete Hegseth and network” for $60 million. I then investigated ten out of Google’s first 14 returns at that time. (Four of these returns did not enable me to uncover the person or group who posted so I skipped those returns.) Each of the ten posting sources I looked at had suspicious anomalies about their authenticity. Below are the results from a few of these ten posts, along with the evidence leading me to believe that these posts are lies, likely malicious clickbait, and showing breadcrumbs that connect them to someone in Asia…
Danel Foster posted this lie to the David Attenborough Fan group on November 27. This fan group has over 790K members! The Daniel Foster Facebook account had 8 friends on December 9, five of whom have very foreign-sounding names, such as Anahita Singh Shukla. Though the first name of Daniel Foster’s account is spelled in the typical male spelling for “Daniel,” the profile photo is that of a woman. Her profile photo looked very similar to the types of AI-generated photos I’ve seen on websites such as generated.photos/faces. I contacted Professor Hany Farid, co-founder of Get Real Security. He and his company specialize in identifying AI-generated content. Mr. Farid told us “Our forensic analysis suggests that this is a GAN-generated face (e.g. from thispersondoesnotexist.com).” (Wikipedia meaning of GAN-generated.) This confirmed that the photo of Daniel Foster is fake. Daniel Foster’s Facebook account also claims that she started to work at PacifiCare Health Systems Incorporated in July, 2025. However, this Health Care business was acquired by United Health Group in 2005 and is no longer an independent company. And her profile says she studies at Fortis College but lives in Seattle, Washington. There is no branch of Fortis College in the state of Washington, according to their website. Her Facebook account had only 3 photos and, according to Facebook, she just joined the David Attenborough group on November 20, a week before she made the suspicious post. (Oddly, one of the three photos is of the hood of a taxi. This photo can be found on dozens of sites across the world, including many in India and other parts of Asia.) At least six of her many posts since November 22 include links to ifeg[.]info NOTE: ifeg[.]info claims to be a “News & Media” website. It contains recipes and a variety of articles. At the bottom of the main page is text that says “Older Articles” in the Vietnamese language (Bài viết cũ hơn). There is also the Vietnamese word for “Next” (Tiếp theo). There is NO INFORMATION whatsoever on this website as to who owns it, where they are located, or other information to legitimize this website. It is highly suspicious!
The Facebook Group called Movie Quotes (with nearly 860K members) shows a suspicious post by an account identified as “Heavenly Blooms” However, the actual Facebook link for the Heavenly Blooms account shows that it was created for a man named Gabriel Enrique Castro. His Facebook account joined the Movie Quotes Facebook group recently on November 14, 2025. The personal Facebook account for Heavenly Blooms shows many posts up to November, 2015. But then there are no posts for 10 years, until the suspicious post about the $60 Million lawsuit against Pete Hegseth lawsuit appeared on Movie Quotes on November 23, 2025. In fact, many suspicious posts have been made to the Movie Quotes Facebook Group by Heavenly Blooms, beginning on November 15, the day after joining this group. (However, none of these posts can be found on his personal account.) On December 3, at 3:03 AM, Heavenly Blooms dropped a post about Dolly Parton visiting Phil Collins in the hospital. This post also included a link to ifeg[.]info (NOTE: According to Google’s AI “While there are many heartwarming, viral social media posts from late 2025 describing Dolly Parton visiting Phil Collins in the hospital, bringing flowers and singing “Yesterday,” these stories appear to be fabrications or AI-generated narratives, as there are no credible news reports or verified sources confirming such an event”) (NOTE: By December 12, it appears to us that this post by Heavenly Blooms was removed from the Movie Quotes FB Group.)
On November 19, Erlimar Christo made a Facebook Post to the National Weather Service Facebook Group claiming that Barron Trump, 19, turns Senate hearing into a 10 minute masterclass. (The National Weather Service Facebook Group has nearly 983K members.) This post also contains a link to ifeg[.]info This post is a lie and identified as such on Snopes.com. Erlimar Christo’s Facebook profile says he lives in Brazil and has 187 friends. Why would a Brazilian native leave a non-weather-related, political post on the United States National Weather Service Facebook group? Oddly, his personal Facebook account shows 7 posts between November, 2012 and August, 2013 and then no more posts to his Facebook account. He hasn’t updated his profile picture since 2013. However, he joined the US National Weather Facebook Group on November 12, 2025 and made multiple posts to this Group since then. Many of these posts have nothing to do with weather.
On December 2, 2025, Admin moderator Fahema Akther posted “ROCK LEGEND REBORN! Keith Richards Stuns Fans with a Bold New Look That’s Breaking the Internet” and more. Her post included a fake, AI-manipulated photo of Keith Richards and a link to the “complete article” at a suspicious website called print-styles[.]shop. This domain was registered very recently on October 29. DomainTools.com’s WHOIS tool captured a screenshot of this website. This screenshot shows no content on this website. However, at the bottom of their screenshot, print-styles[.]shop shows their phone number as +1-855-999-7840. This phone number has been linked to fraud and other fraudulent/suspicious websites many times on social media posts, and very credible sources such as the BBB.org. Below is a screenshot of Fahema Akther’s post and the Keith Richards photo. Notice that in the lower right corner of the photo there is a symbol indicating this picture was AI-generated and is NOT REAL. Again, I contacted Professor Hany Farid, co-founder of Get Real Security to confirm this. He said “This visible watermark is from Google’s Gemini, which I can additionally confirm because I was also able to extract an invisible watermark which identifies this as AI generated.” By the way, Fahema Akther became a moderator of the Rolling Stones Fans Facebook group recently on September 9, 2025. This fan group was created on April 25, 2025, less than 8 months ago and has more than 28K members. Fahema’s Facebook Profile shows 36 friends and only 2 identical photos posted on her account as of December 11. The photos show a woman who is likely with her daughter. According to Google, the origin of her name is Arabic and Persian, particularly from Southeast Asia. Also note that on December 11, I conducted a reverse image search of the exact AI-generated photo of Keith Richards (seen below.) Google found it on 39 different social media pages, going back 9 months. At least 30 of these photos were posted in the last four months and 37 of all 39 posts were found on Facebook.
In late June, 2017, a Facebook Group was created called “What’s For Today.” It has more than 1.1 Million followers! The contact information for the group admin is shown as +84 167 777 7777. “+84” is the International calling code for Vietnam. It also seems a bit coincidental that their email address is listed as social9.vn@gmail.com which also uses the 2-letter country code for Vietnam: “vn”. The Admin of this Group are very active. On December 3, for example, the Admin for this Facebook Group posted articles, accompanied by graphics, seven times. During the week from November 26 to December 3, the Admin posted incredible stories more than 52 times to this Facebook group! Each post included a link to the “full story” and that link pointed to a domain that VirusTotal’s team has identified as malicious. That malicious domain is usnews24today[.]com. Sucuri.net also found an anomaly on one of these links that it said **could be** malware. That particular post, about “JonBenet Ramsey’s Mystery” is suspicious for possible malware. It was made minutes before I found it here on Facebook. (DO NOT CLICK the link if you visit the Facebook post!) This happened again, on December 12, as I were working on this article. Another post made to this Facebook Group contained a link pointing to usnews24today[.]com that Sucuri.net says **could be** malware. The post began with “The TRUE Identity Of ‘D.B. Cooper’ Has FINALLY Been Revealed!” Below are several screenshots of recent posts on the What’s For Today Facebook Group. Note that they all include links to this malicious “US news” website. Also, the post about Journalist Linda Moulton Howe contains photos that were AI manipulated by a tool called SnapEdit. Once again, I could not find any credible source to verify the information in this post.
On December 4, a Facebook Group named “Light Through Laughter” posted a quote supposedly attributed to Jon Stewart. (DO NOT CLICK ANY links if you visit this Facebook Group!) The post begins by saying… “ JON STEWART JUST WENT FULL NEW YORK ON TRUMP IN A LIVE IMMIGRATION SHOWDOWN You’re breaking families apart — and calling it policy. Shame on you. The studio fell into 17 seconds of dead, breathless silence.” It turns out that this exact quote has also been attributed to Barbra Streisand, as well. (We just learned that Barbra changed the spelling of her birth name “Barbara” to Barbra.”) This post appeared again on December 6, with a link to a suspicious website called balanced[.]blog. (Screenshot below.) This Facebook Group had about 8000 followers on December 8, 2025. I looked more closely at this Facebook Group named “Light Through Laughter” and found many suspicious clues that lead us to believe the creator of this Facebook Group is a fraud from a foreign country, using the topic of “light through laughter” to target Americans. Here’s what I found and why I believe this Group is a malicious fraud…
- The “news & media” Facebook Group named “Light Through Laughter” was created on August 19, 2025 by an organization called Sustainoble Solutions LLC, displaying their address as “BARBARA United States, 93103 United States of America.” The word “sustainable” if obviously misspelled and the address they show is wildly incomplete. A Google search for this so-called news & media business returned a link on bizprofile.net showing a business of this name with an address at 1034 East Montecito Street Santa Barbara, CA 93103. Oddly, Google also informs us that this address is a small, single family home.
- In the 2 weeks from November 28 to December 8, the group admin of Light Through Laughter posted more than 65 times about Jon Stewart. Each post contained a link to an article on a website called balanced[.]blog.This domain was registered on October 9, less than two months before I found it.
- Most importantly, balanced[.]blog has been identified as a phishing fraud on VirusTotal.com.
- Also important to my investigation concerns who is likely behind this fraud. According to the Facebook Group Transparency Page of Light Through Laughter, the primary country/region location of the people who manage this Page include three from Vietnam and two from the Philippines. That’s also odd since the supposed media business behind this FB Group says they are located in Santa Barbara, California!
- I randomly evaluated two other posts made by the Admin of Light Through Laughter. On December 3, a “Light Through Laughter” post reads… “Jon Stewart Diagnosed with Terminal Stage-4 Cancer Just 11 Days Before His World Tour Launch: Doctors Give Him “Weeks, Not Months”; Icon Refuses Treatment, Vows to Give His Final Performance Under the Spotlight.” And on December 5, the admin post reads…”HEARTBREAK IN THE USA — America is stunned as Jon Stewart is suddenly hospitalized after a severe medical complication.” According to Google’s AI responses, both of these posts are lies. (However, in February Jon Stewart did cut his hand on a broken mug during a monologue.)
In the “About” section of this Facebook Group is a heading called “Websites and Social Links.” Under this Heading, Light Through Laughter has listed a website called dailynews[.]topnewsource[.]com. Topnewsource[.]com was registered through Namecheap in Iceland on 7/3/2024 and was also found to be malicious on VirusTotal.com.
On December 9, the Facebook Group called Echos of Elegance posted a message that began with “SHE’S JUST AN OUTDATED DIVA TRYING TO STAY RELEVANT.” That was the line Sunny Hostin let slip live on The View, as the table laughed lightly about Barbra Streisand making a rare daytime TV appearance after years of avoiding talk shows unless necessary. “She’s just a voice from another era who keeps singing the same sentimental ballads — that’s all,” Sunny added with a playful shrug. Joy grinned. Whoopi smirked. Alyssa clapped once, almost out of reflex.” This Facebook Group had 17,000 followers. This exact post can be found in many other Facebook Groups. Outside of posts on Facebook, I have not found any reliable or trustworthy news service that has corroborated this information. It appears to be a lie. Following this post were the words “read more” and a link to the full article on a very suspicious website called quisphere[.]biz. One security service on VirusTotal.com finds this website suspicious and Scam-Detector.com identifies it as “high risk” and “unsafe.” The domain qisphere[.]biz was registered about 6 weeks earlier on October 22.
And again, I found evidence that the people behind the Echos of Elegance Facebook Group are a fraud, with malicious intentions and from Vietnam…
- The Transparency page of the profile for Echos of Elegance states that this Facebook Group was created recently, on July 28, has multiple Admins, and was created by a business identified as “DD Distribution LLC.” There are at least 4 businesses identified by this exact name in the US that I could find and none of them appear to have anything to do with news or media.
- Facebook states that the location of this Group’s Page manager is Vietnam.
- The Contact/Info page of this group’s profile also shows a website called viral[.]cafex[.]biz. Cafex[.]biz was registered in May, 2022 in Iceland, using Namecheap. One security service on VirusTotal.com finds this website to be a phishing fraud.
- The address shown on the Contact/Info page of this group’s profile is 3589 Sycamore Street, Texas City, TX, United States, 95054. However, Zip Code 95054 is for Santa Clara, California and not Texas! Also, according to the results of a Google search, there is no Sycamore Street in Texas City, Texas.
It is important for readers to know that I was only able to investigate a tiny fraction of the dozens and dozens of suspicious posts, Facebook Groups, Accounts, and links to “news/media” websites that I found during this month-long investigation. And each time I explored a post, a Facebook Group, or a link, I discovered more that I did not have the time to investigate! The volume of suspicious/malicious content was overwhelming, even though I invested about 100 hours into this effort in about one month!
MY CONCLUSION: I firmly believe that my investigation has produced a significant amount of evidence showing that agents (cybercriminals) from Asian countries, primarily Vietnam, are making a strong, concerted and significant effort to target Americans with malicious clickbait.
Some of that clickbait may be malware, and some of it may be phishing fraud. I cannot say for certain, except that there is clearly malicious intent. What is also extremely concerning about this malicious fraud is that whomever is behind it is misusing Facebook to target millions of Americans! For example, based on the Facebook Group topic of interest that I found, I believe the number of members who are likely American citizens could easily be nearly two million. Even a conservative estimate that 50% of all of these targeted Facebook Group members are Americans puts the number of Americans with targets on their backs at about one million! Obviously, not everyone believes these malicious fake posts, and not everyone clicks a link to a malicious website. But these posts also contribute to the disinformation campaigns that are significantly dividing our country, and perpetuating lies. Even if a conservative guestimate that 1 in 20 people were to click a malicious link, I think that at least 100,000 people could be victimized by this fraud in some way. And remember, my month-long investigation was just a drop in the bucket of these malicious disinformation campaigns spread across Facebook! This malicious campaign has clearly been going on for at least 9 -12 months, and has significantly ramped up in the last 4 months. And at the end of December, I am still seeing similar posts containing suspicious links, as recently as December 27, 2025.
Admittedly, I don’t know the end-game of the gangs behind this awful fraud. Some readers might think that the lies and outrageous assertions I’ve found posted hundreds of times across Facebook in my month-long investigation is just a form of rage-baiting to generate click money for the people making these fake posts. (To better understand “rage baiting” and the income it can earn, check out this BBC article from December, 2024.) However, I found very limited advertizing on only one of the many suspicious websites I investigated. What is crystal clear to me is that this story needs to get a LOT MORE ATTENTION! Major mainstream news services need to understand it and report it to their viewers and listeners. The FBI needs to investigate it and, most of all, Facebook (Meta) needs to do a much better job at identifying these threats and stopping them! Please share this story with your friends and family. Please post a link to this story in your social media accounts.
In case the points I made above were not enough to support my contentions, below are a few more…
The table below summarizes the remaining few observations I made about the Facebook posts about lawsuits against “Pete Hegseth and network” for $60 million dollars that I investigated. I discovered another two new very suspicious domains that were posted as links to news-related websites. Also, each account has information that suggests a connection to foreign countries, or to a Facebook profile that has suspicious anomalies indicating some form of fraud or lies.
(“When” in the first column refers to the time that Google gave us relative to my December 4-5 search date. “FB Group” is the Facebook Group on which I found the post and “Who” is the actual account that made the post I investigated.)
| Additional Suspicious/Malicious Websites Found Posted on Facebook in January, 2026 from Various Sources |
| breakingradar[.]com – registered on 12/6/2024 through Namecheap in Iceland; link uses a directory with a Vietnamese name ducthan |
| lipgists[.]com – WARNING: Malware found on site by VirusTotal.com; domain registered on 10/8/2023 through Namecheap in Iceland |
| luxurydiorusa[.]com – registered on 5/11/2024 through Namecheap in Iceland; rated as suspicious/dubious on Scam-Detector.com |
| metronewsline[.]com – suspicious news websites; created on 8/1/2025 through Namecheap in Iceland; link uses a directory with the Vietnamese name of Lananh; rated as suspicious/unsafe on Scam-Detector.com |
| starfocus360[.]com – registered on 12/6/2024 through Namecheap in Iceland; link uses a directory with the Chinese/Vietnamese name of Thuuyen |
| ukwow24[.]com – registered on 10/8/2023 through Namecheap in Iceland; rated as untrustworthy/dangous by Scam-Detector.com; identified as suspicious on VirusTotal.com |
January, 2026 by Someone on Facebook using the Name “Lil Chase.” |
| aerwyn[.]info – registered on 1/10/2026, the same day Lil Chase posted a link to this fake story about Stephen Colbert |
| boldflow[.]forum – registered on 12/11/2025; found on VirusTotal as phishing fraud; post in link by Lil Chase |
| dravex[.]biz – registered on 1/10/2026; just hours later Lil Chase posed a link to this website with a fake story about Kelly Clarkson |
| elnyxo[.]live – registered on 1/10/26 through Namecheap; posted the next day by Lil Chase |
| flowstrength[.]live – registered on 12/11/2025; found on VirusTotal as phishing fraud; |
| lanexo[.]live – registered on 1/10/2026; post by Lil Chase claims Barbra Steisand collapsed in mid-performance. It is a lie |
| peakdash[.]forum – registered on 12/11/2025; Lil Chase posted a link to a story claiming that Donald & Melania Trump were arrested by China |
| sprintpeak[.]info – registered on 12/11/2025; just a few weeks before Lil Chase posted multiple lies on FB with links to this website |
| tigerwave[.]live – registered on 12/11/2025; found on VirusTotal; a few weeks later Lil Chase posted a link to this story claiming Stephen Colbert was in a car crash |
Website Names Found on Suspicious Facebook Posts Investigated in Nov., 2025 |
| 247usanews[.]com – registered through Namecheap in Iceland on 10/4/2025; posted 3x |
| apkclass[.]info – registered on 11/30/2024 through Namecheap in Iceland; found to be malicous on VirusTotal.com |
| artgardenhub[.]com – registered on 8/8/2024 through Namecheap in Iceland |
| asckat[.]com – registered on 8/22/2022 through Namecheap in Iceland; posted 7x |
| auraflow[.]blog – registered on 10/9/2025; found to be malicious on VirusTotal.com |
| azontree[.]com – registered on 7/7/2024 in Lithuania; posted 3x; found to be very malicious on VirusTotal.com including malware! |
| balancepoint[.]blog – registered on 10/8/2025; posted 5x; found to be malicious on VirusTotal.com |
| best-markets[.]shop – registered on 10/31/2024 through Namecheap in Iceland; found to be malicious on VirusTotal.com |
| bloggingplatform[.]org – registered on 3/3/2022 using Namecheap in Iceland; found to be malicious on VirusTotal.com |
| bluebuzznews[.]com – registered on 5/22/25 through Namecheap in Iceland; posted 2x |
| bom[.]so – was registered on 11/15/2021; posted 2x; found to be malicoius on VirusTotal.com and will redirect to a website called petcutes[.]com |
| booknest[.]org – registered through Namecheap in Iceland on 5/31/2019; posted 8x; found to be malicious on VirusTotal.com |
| btuatu[.]com – registered on 10/31/2022 through Namecheap in Iceland; found to be malicious on VirusTotal.com |
| cafex[.]biz – registered on 5/18/2022 through Namecheap in Iceland; found as malicious on VirusTotal.com |
| celebgosship[.]com – registered on 3/19/2025 through Namecheap in Iceland, Sucuri.net shows that this site redirects to Google |
| celebhot[.]com – registered on 7/1/2024 through Namecheap in Iceland; posted 3x; in late Dec. found to be malicious on VirusTotal.com |
| celebupdate24h[.]com – registered through Namecheap in Iceland on 3/19/2025; posted 2x; found as malicious on VirusTotal.com |
| chistats[.]biz – registered on 10/9/2025 |
| chiway[.]info – registered on 10/9/2025; posted 3x; found to be suspicious on VirusTotal.com |
| cloth-shopping[.]shop – link posted 11/17/25, 20 days before domain was registered on 10/29/25; posted 2x |
| clubofsocial[.]com – registered on 9/11/2023 through Namecheap in Iceland; posted 4x, was found to be suspicious on VirusTotal.com but not 1 week later |
| colofandom[.]com – registered on 9/11/2024 through Namecheap in Iceland; posted 3x |
| dailyhotnew[.]com – domain was registered on 7/5/2024 through Namecheap in Iceland; posted 7x, found to be malicious on VirusTotal.com |
| dailymagazine23[.]com – registered on 3/21/2025 |
| dailystory24h[.]com – registered on 11/27/2025 through Namecheap in Iceland |
| dailytruth[.]today – registered on 9/17/2025 through Namecheap in Iceland; MALWARE found by VirusTotal.com |
| echobeat[.]blog – registered on 10/16/25; clicking the link will forward you to the domain livextop.com, which was registered on 8/26/24 and found to be malicious on VirusTotal.com |
| energywin[.]blog – registered 10/9/2025, posted 2x; found as malicious on VirusTotal.com |
| everythingnowon[.]com – registered on 2/20/25 through Namecheap in Iceland; found to be suspicious on VirusTotal.com |
| fcaroyal[.]site – registered on 6/1/25 and is using a Nameserver in Vietnam; posted 2x; directs your click to topnewsource.com and this domain was found to be malicious on VirusTotal.com |
| fcsakura[.]site – was registered on 7/18/2025 and uses a nameserver located in Vietnam; posted 3x |
| feji[.]io – registered on 4/20/2024 through Namecheap in Iceland |
| flowchampion[.]info – posted DOZENS of times, starting on a post about Trevor Noah on 11/9/25, just 1 month before this domain was registered on 10/9/25; found to be malicious on VirusTotal.com |
| flowfitdaily[.]info – posted 9/11/25 (domain registered on 10/9/25), posted 3x; found to be malicious on VirusTotal.com |
| flowhouse[.]blog – registered on 10/9/2025, posted 3x, found to be malicious on VirusTotal.com |
| fnnewsupdate[.]com – registered on 5/19/2025 through Namecheap in Iceland; link uses a directory with the Vietnamese name Hien Pham; |
| fodlai[.]com – was registered on 3/30/2024 through Namecheap in Iceland; posted 2x; found to be malicious on VirusTotal.com |
| forceflow[.]biz – domain registered on 10/9/25; posted 4x; found to be malicious on VirusTotal.com |
| freshhaynews[.]com – registered on 7/13/25 through Namecheap in Iceland |
| fsnews[.]info – domain registered on 10/9/25; posted 3x |
| get-derila-ergo[.]com – registered on 1/30/25 |
| goodstorie.info – registered on 11/8/2024 through Namecheap in Iceland |
| harmonyflow[.]blog – domain registered on 10/8/2025; found to be malicious on VirusTotal.com |
| hollywoodbuzzdaily[.]space – domain was registered on 10/20/25; found to be malicoius on VirusTotal.com |
| hotnews247[.]us – domain was registered on 4/9/2024 through Namecheap by someone from Vietnam named Ta Khanh Thien |
| ifeg[.]info – domain was registered way back on 10/3/2021; posted 5x |
| insightnewshot[.]com – registered on 5/19/25 through Namecheap in Iceland; the link included a directory named Thùy Dung, a Vietnamese name |
| kora-show[.]live – registered on 7/12/2021; domain found to be suspicious on VirusTotal.com |
| livenews24h[.]com – registered on 7/20/2025 through Namecheap in Iceland; posted 4x; found to be suspicious on VirusTotal.com |
| livextop[.]com – registred on 8/26/2024; found to be malicous on VirusTotal.com |
| lumaflow[.]blog – registered on 10/13/2025; found to be malicious on VirusTotal.com |
| musicindustrybuzz[.]site – registred on 7/23/2025; found to be malicious on VirusTotal.com |
| newshour21[.]com – registered on 6/14/2021 using Namecheap in Iceland; posted 3x |
| newsonline[.]biz – registered on 10/14/2024; found to be suspicious on VirusTotal.com |
| nflinsight360[.]com – registered on 7/27/2025 by someone in Vilnius, Lithuania |
| nhawk[.]org – was registered on 9/25/2025 by Quang Nam in Vietnam; the posted link to this website will redirect visitors to virevo.feji.io |
| noteplay[.]org – registered through Namecheap in Iceland on 9/25/25, posted 2x; found to be malicious on VirusTotal.com |
| paradoxfashion[.]shop – registered on 11/20/2024 through Namecheap in Iceland; found to be malicious on VirusTotal.com |
| pollywebart[.]com – registered on 7/19/2024 |
| purerise[.]info – domain was registered on 10/13/25; posted 3x; found to be malicious on VirusTotal.com |
| quietfield[.]org – registered on 7/29/2025 in Vietnam by someone named Quang Nam; found to be VERY malicoius by 13 security services on VirusTotal.com |
| radiantmoon[.]net – registered on 8/30/2025 by someone in Vietnam named Quang Nam; posted 12x; found to be malicious on VirusTotal.com |
| radiantzen[.]info – domain was registered on 10/13/25; posted 3x, found to be malicious on VirusTotal.com |
| sheinee[.]shop – domain was registered on 9/23/25 through Namecheap in Iceland; one month later in late Dec., VirusTotal found this to be malicious! |
| shuihar[.]info – domain was registered on 11/6/25; posted 3x; found to be suspicious on VirusTotal |
| sportylife[.]blog – registered on 10/9/2025; found to be malicious on VirusTotal.com |
| tenderpath[.]net – registered on 8/30/2025 by Quang Nam in Vietnam; posted 4x; found to be malicious on VirusTotal.com |
| todaycnews[.]com – registered on 8/21/2022 through Namecheap in Iceland; posted 2x; link structure contained a top directory using a Vietnames name Tuyetanh in both posts |
| todayusa[.]org – registered by someone in Lithuania on 4/17/2025; found to be very malicious by many services on VirusTotal.com, including malware |
| toolic[.]shop – registered on 3/14/2025 through Namecheap in Iceland |
| top-fan[.]shop – domain registered on 8/24/2025; found to be malicious on VirusTotal.com |
| topnewsaz[.]com – registered on 3/5/2024 through Namecheap in Iceland; posted 2x |
| topnewsource[.]com – domain was registered through Namecheap in Iceland on 7/3/2024; posted 7x; found to be malicious on VirusTotal.com |
| torlib[.]com – registered on 6/10/2024 through Namecheap in Iceland; posted 2x |
| treeiq[.]biz – was registered on 9/30/25 through Namecheap in Iceland |
| trueaura[.]info – registered on 10/13/2025; posted 2x; found to be malicious on VirusTotal.com |
| ukpride24[.]com – was registered on 6/4/2023 through Namecheap in Iceland; this post was made to a Prince Harry FB Group by someone named Kemmy Adeyemi, who has ties to Nigeria |
| uktalkin[.]com – registered on 5/4/2024 through Namecheap in Iceland |
| updatetinus[.]com – was registered on 3/23/2024 through Namecheap in Iceland; posted 2x; 2nd link contained a directory named Thuynguyen, a Vietnamese name |
| updateweb24h[.]com – domain registered through Namecheap in Iceland on 7/7/2025; posted 4x, found to be suspicious on VirusTotal.com and redirects to multiple sites |
| usanews24today[.]com – was registered on 4/17/2025 through Namecheap in Iceland; post on 10/27/25 spells shocked as “sh0cked”; a visit to this website simply redirects you to Google (on 11/25); was found as malicious on VirusTotal.com but not currently |
| usarite[.]com – registered on 2/11/2024 through Namecheap in Iceland |
| usbrekingnews24[.]com – was registered on 8/27/25 throught Namecheap in Iceland; SEE NOTE BELOW! VERY ACTIVE MALICIOUS POSTS FROM Meena Kumari account |
| usdailys[.]com – registered on 7/5/2024 through Namecheap in Iceland; found as malicious on VirusTotal.com |
| usfandom247[.]com – registered on 3/22/2025 through Namecheap in Iceland |
| ustareveryday[.]com – registered on 11/3/2025 through Namecheap in Iceland; link redirects to Google; link top directory uses the name LongTV which is the name of a Internet/media service in Malaysia; found to be suspicious on VirusTotal.com |
| vira.com[.]ng – registered in Nigeria on 12/24/2023 |
| warmswan[.]net – domain was registered on 9/17/25 by Quang Nam from Vietnam |
| zensportz[.]info – registered on 10/9/2025; found to be malicious on VirusTotal.com |
















