Screenshot of a Repsol phishing website repsolhub[.]buzz | Image: Silent Push
A sprawling phishing and scam operation, dubbed βPower Parasitesβ by the threat analysts at Silent Push, is leveraging the credibility of major energy and tech brands to lure unsuspecting individualsβparticularly in Bangladesh, Nepal, and Indiaβinto fraudulent job and investment schemes.
Operating across deceptive websites, Telegram channels, and social media groups, this campaign targets brands like Siemens Energy, Schneider Electric, Repsol S.A., Starlink, Netflix, and others, impersonating their logos, platforms, and executives to facilitate financial fraud and identity theft.
The campaign rose to broader attention in late 2024, when Siemens Energy publicly warned users on Facebook of scam pages misusing its name to promote pyramid investment and fake job offers:
βWe strongly advise the public to refrain from investing or depositing money on any social media or offline platforms claiming to be associated with Siemens Energy.β
Victims receive realistic-looking employment agreements demanding sensitive personal details such as:
- Bank account number & IFSC code
- Passport & birth certificate copies
- A void cheque
βThe threat actor requests that the applicant… provide a βBank account number & Bank IFSC Codeβ along with passport… and a βvoid cheque.ββ
These requests are framed as βjoining formalitiesβ for roles that do not exist.
Silent Push analysts mapped over 150 domains as part of this infrastructure, with naming conventions centered around keywords like se-, amd-, renewables, biz, and top:
Examples include:
- se-renewables[.]info
- amdtop[.]vip
- sehub[.]top
- repsolhub[.]buzz
Domains often featured login pages with βInvitation codeβ fields, a common tactic in investment fraud to discourage outside inspection:
βThe βInvitation codeβ field… is used to make it more difficult for defenders to investigate… without being directly contacted by website operators.β
Promotion of these scams isn’t limited to dark corners of the internet. The campaign has been actively advertised via YouTube, with videos aimed at Bangladeshi and Indian audiences encouraging viewers to βEarn free money from new sites.β
βA second YouTube video… titled in Bangla: βEarn free money from new sitesββ linked directly to scam domains.
In addition, Telegram channels spoofing Siemens Energy were used to funnel victims into scam websites, although most have since been banned.
While many campaigns fall into the broader category of βpig-butcheringβ scamsβa term originally coined for long-term investment frauds where scammers βfattenβ victims with fake gainsβPower Parasites adds a layer of eco-credibility by targeting renewable energy and clean tech brands. These scams were essentially additional financial phishing content gated behind a login. Victims are led to believe they are participating in green investments or prestigious tech job offers.
Repsol and Suncor Energy have both issued public warnings:
βRepsol never requires payment to be involved in a Company recruitment process… It is not common practice to request personal information… by email or telephone.β
Meanwhile, the U.K. Financial Conduct Authority flagged a domain, repsolgain[.]com, as a fraudulent investment platform misusing the Repsol brand.
Interestingly, Silent Push researchers believe this specific domain may be part of a separate campaign, distinct from the main Power Parasites operation, based on technical and visual differences.
Power Parasites is more than just another scam campaign. Itβs a multi-language, multinational operation exploiting the reputations of trusted global brands for monetary gain. With over 150 domains and dozens of platforms compromised or mimicked, this is a call to arms for brand protection teams and cybersecurity defenders alike.
Related Posts:
- Kaspersky Report: Energy Industry becomes the largest area affected by vulnerabilities in industrial automation systems
- Hackers Fake ChatGPT App to Spread Windows, and Android Malware
- Netflix Phishing Scam: Even the Savviest Streamers Can Fall Victim
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.