WhatsApp
HomeAboutExperience Case StudiesResearch CAI InitiativeInsights GitHub & LabsCertifications Contact →
CNTI-2026-001 v2.0 · TLP:WHITE · ICDFA PUBLISHED OSINT INVESTIGATION · THREAT INTELLIGENCE · INTERNSHIP FRAUD
← Back to Case Studies
Threat Intelligence OSINT Investigation · v2.0 · Published to ICDFA Repository

MutaCryptor Scam Network

Correlating MutaEngine, VRV Security, and Zorvyn FinTech into a single global internship-fraud network.

This report documents a coordinated internship fraud network that has actively targeted technology and cybersecurity job seekers globally since at least mid-2024. The operation builds elaborate fake companies — professional websites, employee portals, legally styled offer letters, automated onboarding — then exploits weeks of manufactured trust to solicit Bitcoin payments for a fictitious software product, MutaCryptor, sold by an entity calling itself MutaEngine. Two confirmed fake company shells were identified: VRV Security and Zorvyn FinTech. I was personally targeted by the Zorvyn FinTech operation in April 2026, which let me document the complete 8-phase attack chain firsthand rather than reconstruct it secondhand.

Key Findings
  • MutaEngine accepts payment exclusively via Bitcoin — dynamically rotating wallet addresses, 15-minute invoice expiry, no KYC, no refunds. This is the single strongest indicator of criminal intent: no legitimate software vendor operates this way
  • The network's infrastructure collapsed (NXDOMAIN across all zorvyn.live domains) on 18 April 2026, during active investigation — consistent with a professional operation tearing down after exposure, not amateur actors
  • Correlation analysis across three hypotheses concludes MutaEngine most likely operates all three entities as a single actor, using the fake companies purely as acquisition funnels while maintaining plausible deniability
  • The identity of a real Indian security staffing firm (VRV Security) was stolen and impersonated in an earlier variant of the same operation

The Problem

On 7 April 2026, I received a screening assessment invitation from hr@zorvyn.io for a Cybersecurity Analyst Intern role at "Zorvyn FinTech Pvt. Ltd." After a timed technical assessment, an offer letter followed — signed by a purported CEO, a stipend above market rate, and a pre-placement offer up to ₹16 LPA dangled as a long-term incentive. What followed was a multi-day onboarding process — employee portal, welcome kit, a named reporting manager — that culminated in a "training task" requiring me to purchase software called MutaCryptor from a separate domain. I didn't. This report documents the investigation that followed.

The Approach

I treated this as a structured OSINT investigation from the first suspicious signal, not a reactive complaint:

  • Firsthand documentation — captured the complete email chain, portal screenshots, and offer documentation as the scam unfolded in real time
  • Infrastructure mapping — traced every domain, subdomain, and email address across the Zorvyn operation, and cross-referenced against the earlier VRV Security variant
  • Financial architecture analysis — accessed the Bitcoin payment interface twice to confirm wallet rotation and invoice-expiry behavior, without completing any payment
  • Correlation analysis — built and tested three competing hypotheses for how MutaEngine, VRV Security, and Zorvyn FinTech relate to each other, rather than assuming a single-operator conclusion
  • Report production — structured findings into a formal 20-page TI report (CNTI-2026-001) published to the ICDFA Repository, updated to v2.0 as new evidence (the infrastructure collapse) emerged mid-investigation
OSINT red-flag analysis of a fake recruiter job posting

General fake-recruiter red flags of the kind confirmed in the Zorvyn case: no verifiable company name, suspicious redirect domains, engagement-bait requests

⚠ Investigation boundary

No payment was made at any point. Access to the Bitcoin checkout interface was limited to observing wallet-rotation behavior — sufficient to confirm the payment architecture without funding the operation.

The 8-Phase Attack Chain

The operation follows a long-con trust-building lifecycle — each phase deepens victim commitment before the monetization request:

Attack Chain
Phase 1 Target Acquisition — mass screening invites via Internshala, LinkedIn
Phase 2 Screening & Legitimacy Layer — 90-min timed technical assessment
Phase 3 Offer & Trust Building — formal offer, above-market stipend, NDA, PPO
Phase 4 Onboarding Infrastructure — portal access, welcome kit, PII harvested
Phase 5 Manager Introduction — fake reporting manager, 15-day "training plan"
Phase 6 Monetization Trigger — mandatory MutaCryptor purchase, 48hr deadline
Phase 7 Crypto Payment Extraction — Bitcoin-only, 15-min rotating wallets
Phase 8 Data Retention & Teardown — PII kept regardless of payment, infra torn down
Zorvyn internship fraud — integrated operational model diagram

Integrated operational model — the visible social-engineering trust layer feeding directly into the backend financial exploitation layer

Challenges

Confirming payment infrastructure without funding it. Proving the Bitcoin-only, rotating-wallet architecture required interacting with the checkout flow twice to capture two different wallet addresses — enough to prove automated rotation, without ever completing a transaction that would fund the operation.

Attribution without overclaiming. Rather than asserting a single conclusion, I built three explicit hypotheses (single operator, affiliate fraud, independent exploitation) and weighed evidence against each — Hypothesis A (single operator) was strengthened significantly by the Bitcoin infrastructure being identical across all fronts, but the report documents the reasoning rather than presenting a bare conclusion.

The infrastructure changed under investigation. The domain zorvyn.live collapsed to NXDOMAIN on 18 April, mid-investigation — requiring the report to be updated to v2.0 to document the collapse as evidence in its own right, rather than treating it as an inconvenience.

Selected Indicators of Compromise (18+ total)
TypeIndicatorDescription
Domainzorvyn[.]ioPrimary public domain, Hostinger shared hosting
Domainworkplace.zorvyn[.]liveFake employee portal — NXDOMAIN as of Apr 18
Domainpay.mutaengine[.]cloudBitcoin payment gateway
Domainvrvsecurity[.]inPrior shell company, ScamAdviser trust score 2/100
BTC Walletbc1qqe3efq079rymkjer2...eks50kConfirmed rotating wallet, observed ~14 Apr 2026
BTC Walletbc1qvgka8h7z2wzu7jzqc...ul84aConfirmed rotating wallet, observed ~16 Apr 2026
PersonRaj Kishor PattnaikFake CEO persona on offer letter
PersonMudiwa MkontoFake reporting manager persona
MITRE ATT&CK Mapping
T1566Initial AccessPhishing — mass distribution of fake screening invitations via legitimate job platforms
T1583Resource DevelopmentEstablish Infrastructure — custom domains, employee portals, payment gateways
T1584Resource DevelopmentCompromise Infrastructure — real VRV Security identity stolen and impersonated
T1587Resource DevelopmentDevelop Capabilities — AI-generated synthetic employee personas
T1567ExfiltrationExfiltration Over Web Service — victim PII submitted to attacker-controlled portals

Results

  • Formal 20-page TI report (CNTI-2026-001, v2.0) published to the ICDFA Publications Repository, TLP:WHITE for unrestricted sharing
  • First structured investigation to correlate all three entities — MutaEngine, VRV Security, Zorvyn FinTech — into a single documented network analysis
  • 18+ IOCs and 3 confirmed Bitcoin wallets documented with confidence ratings, ready for law-enforcement referral (EFCC, CBI, Interpol per the report's own recommendations) and blockchain analysis
  • Now the top search result for the network's name — the report itself is functioning as the public warning it was designed to be

Lessons Learned

Being personally targeted turned out to be an asset, not just a risk — it enabled a level of firsthand evidence (the full email chain, direct interaction with the payment interface) that reconstructing the scam secondhand from victim reports never could have produced. It also reinforced a specific analytical discipline: presenting competing hypotheses with evidence for and against, rather than jumping straight to the most likely conclusion, makes the report more defensible and more useful to anyone who has to act on it.

What I'd Improve

  • Engage a blockchain analysis specialist to trace the confirmed wallets through mixing services toward a master wallet, rather than stopping at wallet-rotation confirmation
  • Formalize a coordinated disclosure process with Internshala and LinkedIn directly, alongside publishing the public report
  • Build a repeatable infrastructure-mapping template so a future shell-company variant of this same network can be correlated faster

References

  1. Full 20-page report — ICDFA Publications Repository, CNTI-2026-001 v2.0 (TLP:WHITE)
  2. MITRE ATT&CK — T1566 Phishing