“Decoding Political Violence with OSINT and Lessons from the Frontline”

Join deep dive: Wed, Dec 18, 16:00 CET
07 Dec 2023

Fighting Resale of Counterfeit Goods Using OSINT and Maltego

Maltego Team

The online marketplace has opened up possibilities for consumers to easily purchase goods and take advantage of the best deals they find online. A popular trend includes influencers on prominent social media platforms promoting luxury goods and other products with enticing discounts.

Often, people are naturally excited to take advantage of these promotions without fully considering the potential consequences for themselves and the market. Sometimes, knowingly or unknowingly, what they assume to be a good deal is, in fact, a successful attempt at marketing a counterfeit product.

In this article, we will discuss the consequences of the illegal resale of counterfeit goods for companies and users, the difficulties investigators face in probing these activities, and demonstrate how you can use Maltego to protect your goods effectively.


The Scale of the Counterfeit Market in Numbers 🔗︎

A report by Visual Capitalist reveals that over 25% of consumers have inadvertently purchased non-genuine products online, while the U.S. Government Accountability Office study found that around 43% of brand-name items bought through third-party online retailers were counterfeit.

The economic repercussions for companies and brands are immense. The National Association of Manufacturers reports that counterfeit products account for 3.3% of global merchandise trade, costing the U.S. economy about $131 billion and 325,000 jobs in 2019 alone. At the same time, The Guardian estimates that up to 10% of all branded goods sold could be counterfeit.

Source: OECD

Want to start investigating counterfeiters right away? Download your free cheat sheet with step-by-step guidance and replicate the workflow in your Maltego now.

Consequences for Users and Businesses 🔗︎

Counterfeiting impacts both the manufacturing and services industries, affecting sectors such as luxury goods, pharmaceuticals, and electronics.

While it may seem that counterfeiting only causes minor economic harm through the sale of inferior quality products and primarily affects big businesses, this illicit practice may pose significant risks to consumer health and safety due to the lack of quality and safety standards in counterfeit products, such as drugs.

For businesses, counterfeits siphon off market share, revenue, and profits from legitimate businesses and can erode consumer trust in authentic brands, as consumers may associate the inferior quality of counterfeit items with the genuine brands.

Finally, the counterfeit market is frequently intertwined with organized crime, with profits potentially fueling other illegal activities such as drug trafficking and money laundering.


Challenges and Solutions When Combatting Counterfeit Sales 🔗︎

Even though combatting the sale of counterfeit goods seems straightforward (identify the goods, reduce the search scope, and identify the sellers) the reality is more complex.

Let’s look at the associated problems of the usual workflow for combatting counterfeiting and what Maltego can do for you to solve these problems.

Discovery of Counterfeiters 🔗︎

Problem:

  • Counterfeiters constantly evolve their methods. They change sales strategies, utilize various platforms, and alter product marketing. The discovery of counterfeit products and their sellers is dynamic; they might directly approach potential buyers or use their influence on social media.

Solution:

  • Investigators can rely on gathering all possible intelligence on where and how goods and services that are counterfeit are being sold. At the same time, they study their own data to identify networks and connections.
  • Maltego makes it easier for investigators to connect and analyze data from open sources, internal databases, and even the deep and dark web in real-time. This facilitates the visualization of data relationships, assisting investigators in uncovering and mapping out the digital trails left by counterfeiters, including those left on social media profiles and closed groups.

Different Types of Pivot Points 🔗︎

Problem:

  • Investigative breadcrumbs could be a seller’s online post, a phone number, an email address, or even just a social media handle. Working without a unified tool makes tracking and reporting these diverse pivot points challenging.

Solution:

  • A unified interface that aggregates data from different databases can streamline the collection and analysis of various pivot points, enabling investigations to be scaled up without adding to the investigators’ workload.
  • Maltego allows investigators to start their search from various entry points – be it a username, email, image, location, or phone number – and analyze them in a unified interface. This integration simplifies the process and ensures efficient tracking and reporting.

Language Constraints 🔗︎

Problem:

  • Investigators often encounter language barriers. Counterfeiters use various languages and specific jargon or slang, making it challenging for those unfamiliar with the language.

Solution:

  • To overcome these barriers, investigators opt for translation tools and machine learning solutions to analyze language, identify key patterns, and decode complex jargon.
  • Maltego addresses this challenge by providing translation Transforms within the tool and the option to add notes, aiding investigators in overcoming language barriers and ensuring efficient collaboration among team members.

Time-Consuming Repetitive Tasks 🔗︎

Problem:

  • OSINT investigations can be time-consuming, filled with repetitive tasks like searching for specific keywords, images, and pivot points. Each discovery, such as a phone number or email, requires a specific response, adding to the workload.

Solution:

  • This process can be streamlined by developing ready-made workflows. This will involve mapping out an investigation process, identifying areas with repetitive tasks, and then simplifying or automating these steps.
  • In Maltego, investigators can use the so-called Maltego Machines to automate patterns of Transforms run on a regular basis in a set sequence, mirroring their manual operation.


Unveiling Online Counterfeit Threats with Maltego 🔗︎

Investigating unauthorized sales by digital and offline resellers is challenging not only for the reasons previously mentioned but also because illicit sellers adeptly blend into popular e-commerce and social media platforms, marketing counterfeit goods alongside legitimate ones. This complexity complicates identification and intervention.

By using keywords or images of illicit goods, investigators can use Maltego to map out networks of companies and individuals involved in counterfeit goods resale, aiding in the development of effective counter-strategies. Let’s see two ready workflows you can follow.

Tracking Counterfeit Resellers on Social Media Using Keywords as Input Entities 🔗︎

One method to identify illegal resellers using Maltego, especially when you have no initial suspects, is by utilizing common keywords associated with the sale of illegal goods.

INVESTIGATOR INSIGHT: Using this workflow, your approach to identifying illegal resellers will be more targeted, especially when initial suspects are unknown. This method capitalizes on pattern recognition and the commonly used terminology in the counterfeit market.

  • STEP 1

As a starting point, you can employ the Google Dorking search operator site: along with keywords like your company or product name plus some terms that are commonly used among illegal resellers, such as ‘first copy’, ‘duplicate’, ‘replica’, or ‘knockoff’, to refine your search. Alternatively, you could also try variations in the spelling of the brand or product name.

This approach often returns a list of websites, including social media posts, where these keywords are used.

Google dorks are useful tools that can significantly improve your corporate and fraud investigations. Download the full list of useful Google search operators for OSINT investigators.

  • STEP 2

From these URLs, Maltego’s Transforms can be used to extract various Entities such as usernames, phone numbers, and email addresses found on those websites. These details can lead to other related social media profiles.

  • STEP 3

Further investigation can reveal additional information about locations and accounts associated with these profiles. This information is crucial for conducting investigations into persons of interest or companies, helping to gauge the extent of the problem and gather sufficient data for reporting to relevant social media platforms or for initiating legal action.

  • STEP 4

Investigators can also use discovered phone numbers or email addresses as starting points, checking them against breach data within Maltego to build a holistic picture of a subject’s online presence and measure the extent of their potentially illegal activities. This includes locations, contact numbers, emails, names of individuals, associated companies, and more.


Identifying Illegal Resellers on Social Media Using Images as Input Entities 🔗︎

Fraud analysts can also identify illegal resellers of counterfeit goods by analyzing images of counterfeit products that they post on social media platforms, such as Instagram or TikTok, and their websites.

INVESTIGATOR INSIGHT: As investigators, you might find images of products that are not the stock images used by the brand for advertising. Instead, these images could show the counterfeit products being held by the seller or placed in a unique setting. For instance, consider a product seen on popular e-commerce websites that are drop-shipped from a seller in another country. If you search using the images from the e-commerce site, there’s a chance you might find the original seller or the network using the same product.

  • STEP 1

The investigation begins by extracting posts and images from a single social media profile. For example, an Instagram account with numerous images of products promoted for sale by an unauthorized reseller.

  • STEP 2

Focusing on one of the extracted images, this image serves as the starting point for analysis in Maltego. It allows analysts to pivot to other websites where the image is posted, helping to assess the extent of the counterfeit goods’ availability.

  • STEP 3

A quick search will yield a list of websites advertising the product from the original image for sale, providing substantial results for fraud analysts.

In Maltego, it’s also possible to delve deeper to determine if any of these websites are linked to additional counterfeit sites or to each other.

  • STEP 4

By exploring relationships between these websites, investigators may find, for example, IP addresses, Google Analytics tags, and other indicators on their graph, offering further avenues for investigation.


This workflow, like many other repetitive tasks, can be easily automated using Maltego Machines. To learn how to create your own custom Machines, which, for example, can help identify individuals and networks associated with counterfeit goods sold online using a single image as your input Entity, check out our guidebook. It provides detailed instructions on building your custom Machine and integrating it into your daily investigations.

Access Your Free Resources 🔗︎

If you’re interested in starting investigations on counterfeiters using Maltego, or if you want an in-depth overview of a sample investigation, remember to download your copy of the cheat sheet with a ready workflow.

Download the resource

DE +49
Albania +355
Algeria +213
Andorra +376
Angola +244
Anguilla +1264
Antigua And Barbuda +1268
Argentina +54
Armenia +374
Aruba +297
Australia +61
Austria +43
Azerbaijan +994
Bahamas +1242
Bahrain +973
Bangladesh +880
Barbados +1246
Belarus +375
Belgium +32
Belize +501
Benin +229
Bermuda +1441
Bhutan +975
Bolivia +591
Bosnia and Herzegovina +387
Botswana +267
Brazil +55
Brunei Darussalam +673
Bulgaria +359
Burkina Faso +226
Burundi +257
Cambodia +855
Cameroon +237
Canada +1
Cape Verde +238
Cayman Islands +1345
Central African Republic +236
Chile +56
China +86
Cote d'Ivoire +225
Colombia +57
Comoros +269
Congo +242
Cook Islands +682
Costa Rica +506
Croatia +385
Cuba +53
Cyprus +90392
Czech Republic +42
Denmark +45
Djibouti +253
Dominica +1809
Dominican Republic +1809
Ecuador +593
Egypt +20
El Salvador +503
Equatorial Guinea +240
Eritrea +291
Estonia +372
Ethiopia +251
Falkland Islands (Malvinas) +500
Faroe Islands +298
Fiji +679
Finland +358
France +33
French Guiana +594
French Polynesia +689
Gabon +241
Gambia +220
Georgia +995
Germany +49
Ghana +233
Gibraltar +350
Greece +30
Greenland +299
Grenada +1473
Guadeloupe +590
Guam +671
Guatemala +502
Guinea +224
Guinea-Bissau +245
Guyana +592
Haiti +509
Honduras +504
Hong Kong +852
Hungary +36
Iceland +354
India +91
Indonesia +62
Iran, Islamic Republic of +98
Iraq +964
Ireland +353
Israel +972
Italy +39
Jamaica +1876
Japan +81
Jordan +962
Kazakhstan +7
Kenya +254
Kiribati +686
Korea, Democratic People's Republic of +850
Korea, Republic of +82
Kuwait +965
Kyrgyzstan +996
Lao People's Democratic Republic +856
Latvia +371
Lebanon +961
Lesotho +266
Liberia +231
Libyan Arab Jamahiriya +218
Liechtenstein +417
Lithuania +370
Luxembourg +352
Macao +853
Macedonia, the former Yugoslav Republic of +389
Madagascar +261
Malawi +265
Malaysia +60
Maldives +960
Mali +223
Malta +356
Marshall Islands +692
Martinique +596
Mauritania +222
Mauritius +230
Mayotte +269
Mexico +52
Micronesia, Federated States of +691
Moldova, Republic of +373
Monaco +377
Mongolia +976
Montserrat +1664
Morocco +212
Mozambique +258
Myanmar +95
Namibia +264
Nauru +674
Nepal +977
Netherlands +31
New Caledonia +687
New Zealand +64
Nicaragua +505
Niger +227
Nigeria +234
Niue +683
Norfolk Island +672
Northern Mariana Islands +670
Norway +47
Oman +968
Pakistan +92
Palau +680
Panama +507
Papua New Guinea +675
Paraguay +595
Peru +51
Philippines +63
Poland +48
Portugal +351
Puerto Rico +1787
Qatar +974
Reunion +262
Romania +40
Russian Federation +7
Rwanda +250
San Marino +378
Sao Tome and Principe +239
Saudi Arabia +966
Senegal +221
Serbia +381
Seychelles +248
Sierra Leone +232
Singapore +65
Slovakia +421
Slovenia +386
Solomon Islands +677
Somalia +252
South Africa +27
Spain +34
Sri Lanka +94
Saint Helena +290
Saint Kitts and Nevis +1869
Saint Lucia +1758
Sudan +249
Suriname +597
Swaziland +268
Sweden +46
Switzerland +41
Syrian Arab Republic +963
Taiwan +886
Tajikistan +7
Thailand +66
Togo +228
Tonga +676
Trinidad and Tobago +1868
Tunisia +216
Turkey +90
Turkmenistan +993
Turks and Caicos Islands +1649
Tuvalu +688
Uganda +256
United Kingdom +44
Ukraine +380
United Arab Emirates +971
Uruguay +598
United States +1
Uzbekistan +7
Vanuatu +678
Holy See (Vatican City State) +379
Venezuela +58
Viet Nam +84
Virgin Islands, British +84
Virgin Islands, U.S. +84
Wallis and Futuna +681
Yemen +967
Zambia +260
Zimbabwe +263

By clicking on "Access", you agree to the processing of the data you entered and you allow us to contact you for the purpose selected in the form. For further information, see our Data Privacy Policy.

For a more interactive learning experience, watch a webinar recording featuring Maltego’s subject matter experts. They delve deeper into combating counterfeit goods, demonstrating the workflows mentioned in this article. Each step is explained in detail, focusing on key aspects to consider and outlining the next steps in your investigation.

Don’t forget to follow us on Twitter, LinkedIn, and Mastodon, and sign up to our email newsletter, so you don’t miss out on updates and news!

Happy Investigating!

By clicking on "Subscribe", you agree to the processing of the data you entered and you allow us to contact you for the purpose selected in the form. For further information, see our Data Privacy Policy.