This report documents a coordinated internship fraud network that has actively targeted technology and cybersecurity job seekers globally since at least mid-2024. The operation builds elaborate fake companies — professional websites, employee portals, legally styled offer letters, automated onboarding — then exploits weeks of manufactured trust to solicit Bitcoin payments for a fictitious software product, MutaCryptor, sold by an entity calling itself MutaEngine. Two confirmed fake company shells were identified: VRV Security and Zorvyn FinTech. I was personally targeted by the Zorvyn FinTech operation in April 2026, which let me document the complete 8-phase attack chain firsthand rather than reconstruct it secondhand.
- MutaEngine accepts payment exclusively via Bitcoin — dynamically rotating wallet addresses, 15-minute invoice expiry, no KYC, no refunds. This is the single strongest indicator of criminal intent: no legitimate software vendor operates this way
- The network's infrastructure collapsed (NXDOMAIN across all zorvyn.live domains) on 18 April 2026, during active investigation — consistent with a professional operation tearing down after exposure, not amateur actors
- Correlation analysis across three hypotheses concludes MutaEngine most likely operates all three entities as a single actor, using the fake companies purely as acquisition funnels while maintaining plausible deniability
- The identity of a real Indian security staffing firm (VRV Security) was stolen and impersonated in an earlier variant of the same operation
The Problem
On 7 April 2026, I received a screening assessment invitation from hr@zorvyn.io for a Cybersecurity Analyst Intern role at "Zorvyn FinTech Pvt. Ltd." After a timed technical assessment, an offer letter followed — signed by a purported CEO, a stipend above market rate, and a pre-placement offer up to ₹16 LPA dangled as a long-term incentive. What followed was a multi-day onboarding process — employee portal, welcome kit, a named reporting manager — that culminated in a "training task" requiring me to purchase software called MutaCryptor from a separate domain. I didn't. This report documents the investigation that followed.
The Approach
I treated this as a structured OSINT investigation from the first suspicious signal, not a reactive complaint:
- Firsthand documentation — captured the complete email chain, portal screenshots, and offer documentation as the scam unfolded in real time
- Infrastructure mapping — traced every domain, subdomain, and email address across the Zorvyn operation, and cross-referenced against the earlier VRV Security variant
- Financial architecture analysis — accessed the Bitcoin payment interface twice to confirm wallet rotation and invoice-expiry behavior, without completing any payment
- Correlation analysis — built and tested three competing hypotheses for how MutaEngine, VRV Security, and Zorvyn FinTech relate to each other, rather than assuming a single-operator conclusion
- Report production — structured findings into a formal 20-page TI report (CNTI-2026-001) published to the ICDFA Repository, updated to v2.0 as new evidence (the infrastructure collapse) emerged mid-investigation
General fake-recruiter red flags of the kind confirmed in the Zorvyn case: no verifiable company name, suspicious redirect domains, engagement-bait requests
No payment was made at any point. Access to the Bitcoin checkout interface was limited to observing wallet-rotation behavior — sufficient to confirm the payment architecture without funding the operation.
The 8-Phase Attack Chain
The operation follows a long-con trust-building lifecycle — each phase deepens victim commitment before the monetization request:
Phase 2 Screening & Legitimacy Layer — 90-min timed technical assessment
Phase 3 Offer & Trust Building — formal offer, above-market stipend, NDA, PPO
Phase 4 Onboarding Infrastructure — portal access, welcome kit, PII harvested
Phase 5 Manager Introduction — fake reporting manager, 15-day "training plan"
Phase 6 Monetization Trigger — mandatory MutaCryptor purchase, 48hr deadline
Phase 7 Crypto Payment Extraction — Bitcoin-only, 15-min rotating wallets
Phase 8 Data Retention & Teardown — PII kept regardless of payment, infra torn down
Integrated operational model — the visible social-engineering trust layer feeding directly into the backend financial exploitation layer
Challenges
Confirming payment infrastructure without funding it. Proving the Bitcoin-only, rotating-wallet architecture required interacting with the checkout flow twice to capture two different wallet addresses — enough to prove automated rotation, without ever completing a transaction that would fund the operation.
Attribution without overclaiming. Rather than asserting a single conclusion, I built three explicit hypotheses (single operator, affiliate fraud, independent exploitation) and weighed evidence against each — Hypothesis A (single operator) was strengthened significantly by the Bitcoin infrastructure being identical across all fronts, but the report documents the reasoning rather than presenting a bare conclusion.
The infrastructure changed under investigation. The domain zorvyn.live collapsed to NXDOMAIN on 18 April, mid-investigation — requiring the report to be updated to v2.0 to document the collapse as evidence in its own right, rather than treating it as an inconvenience.
| Type | Indicator | Description |
|---|---|---|
| Domain | zorvyn[.]io | Primary public domain, Hostinger shared hosting |
| Domain | workplace.zorvyn[.]live | Fake employee portal — NXDOMAIN as of Apr 18 |
| Domain | pay.mutaengine[.]cloud | Bitcoin payment gateway |
| Domain | vrvsecurity[.]in | Prior shell company, ScamAdviser trust score 2/100 |
| BTC Wallet | bc1qqe3efq079rymkjer2...eks50k | Confirmed rotating wallet, observed ~14 Apr 2026 |
| BTC Wallet | bc1qvgka8h7z2wzu7jzqc...ul84a | Confirmed rotating wallet, observed ~16 Apr 2026 |
| Person | Raj Kishor Pattnaik | Fake CEO persona on offer letter |
| Person | Mudiwa Mkonto | Fake reporting manager persona |
Results
- Formal 20-page TI report (CNTI-2026-001, v2.0) published to the ICDFA Publications Repository, TLP:WHITE for unrestricted sharing
- First structured investigation to correlate all three entities — MutaEngine, VRV Security, Zorvyn FinTech — into a single documented network analysis
- 18+ IOCs and 3 confirmed Bitcoin wallets documented with confidence ratings, ready for law-enforcement referral (EFCC, CBI, Interpol per the report's own recommendations) and blockchain analysis
- Now the top search result for the network's name — the report itself is functioning as the public warning it was designed to be
Lessons Learned
Being personally targeted turned out to be an asset, not just a risk — it enabled a level of firsthand evidence (the full email chain, direct interaction with the payment interface) that reconstructing the scam secondhand from victim reports never could have produced. It also reinforced a specific analytical discipline: presenting competing hypotheses with evidence for and against, rather than jumping straight to the most likely conclusion, makes the report more defensible and more useful to anyone who has to act on it.
What I'd Improve
- Engage a blockchain analysis specialist to trace the confirmed wallets through mixing services toward a master wallet, rather than stopping at wallet-rotation confirmation
- Formalize a coordinated disclosure process with Internshala and LinkedIn directly, alongside publishing the public report
- Build a repeatable infrastructure-mapping template so a future shell-company variant of this same network can be correlated faster
References
- Full 20-page report — ICDFA Publications Repository, CNTI-2026-001 v2.0 (TLP:WHITE)
- MITRE ATT&CK — T1566 Phishing