Inside Elegy
BLOG

Inside Elegy: AI-Assisted Marketplace Fraud Using Haronrent Infrastructure

PUBLISHED SEP 23, 2026 BY Varadharajan Krishnasamy

Rubrik Zero Labs details a Windows-based tool that provides an end-to-end platform for online marketplace scams

Online marketplace scams often begin with a normal seller listing. A scammer poses as a genuine buyer and starts with ordinary questions about availability, condition, price, or delivery to establish trust rather than immediately sending a phishing link.

Once the seller agrees to proceed, the buyer claims that payment has been completed through the marketplace. The seller may then receive a convincing marketplace-style notification, order page, QR code, PDF, or link containing real listing details such as the product name and price. The seller is encouraged to follow payment or order instructions that may claim an order must be confirmed, payment received, an account verified, or an additional security step completed.

The final objective varies between campaigns, but these flows commonly attempt to collect sensitive information such as banking details, payment card data, marketplace credentials, or other account information.

Elegy - From Seller Discovery to AI-Assisted Fraud

Rubrik Zero Labs has identified a Windows-based tool named Elegy v7.3.4 that provides operators with an end-to-end platform for conducting online marketplace scams. Rather than relying on a single phishing message, Elegy manages the broader workflow: identifying real marketplace listings, contacting sellers, maintaining believable conversations, and moving those conversations toward a fraudulent payment stage.

Elegy operates primarily through a browser extension. Its native Windows launcher prepares the environment, extracts the extension from embedded resources, creates working directories, and prepares separate Chrome profiles for the main interface and individual Gmail accounts. The extension then handles marketplace data, campaign Bundles, Gmail automation, AI-assisted buyer conversations, reply monitoring, transaction-related content, and campaign state.

Elegy extension components and browser extension
Figure 1: Elegy extension components and browser extension

The extension also interacts directly with Gmail to identify active accounts, monitor inbox activity, read seller messages, extract sender, subject, and conversation history, and compose or reply in the same thread. Elegy supplies AI with listing context - including product, price, marketplace, country, and seller information - so replies can adapt to what the seller actually says rather than relying only on fixed templates.

The sample supports at least 16 marketplace and classified-advertising platforms and can manage multiple Gmail accounts at once. Elegy tracks worker availability, conversation assignments, and whether previous messages were sent, allowing activity to be distributed across managed browser profiles.

Haronrent Workflow
Figure 2: Elegy and Haronrent Workflow

Once the seller agrees to proceed, Elegy can contact the Haronrent backend server at haronrent.xyz to generate seller-specific phishing content, including transaction pages and links. Elegy can then package or deliver the resulting material through QR codes, PDFs, HTML, and email. The tool also includes a Russian-language operator guide that provides step-by-step usage instructions.

Profiles and Campaign Configuration

Elegy uses managed Chromium profiles to keep Gmail cookies, browser data, and authenticated sessions separated. Operators can create a profile or import an existing Chrome or Edge profile, sign in to Gmail, and register the available account as a worker. These workers send initial messages, monitor seller replies, and continue conversations in the correct Gmail thread.

Profile configuration and Gmail worker setup
Figure 3: Profile configuration and Gmail worker setup

Campaign behavior is packaged into reusable Bundles. The bundle wizard covers four stages: Platform & Payment, Messages & Flow, QR Design, and Review & Test. This groups the marketplace, country, messaging behavior, delivery method, and final validation into a reusable campaign configuration.

 

Bundle configuration with Platform & Payment/Messages & Flow.
Figure 4: Bundle configuration with Platform and Payment/Messages and Flow

In Platform & Payment, the operator selects the marketplace and country. Elegy maps that selection to an internal Haronrent service code such as vinted_de or olx_pl. The interface label "Payment Service" refers to these service codes rather than identifiable payment processors. Mail-service names such as HYPE or CROCO are likewise internal values passed to Haronrent when requesting email delivery. Buyer address information can be supplied manually or generated with AI and saved with the Bundle to maintain a consistent buyer identity.

Messages & Flow defines how the seller is approached and how the interaction progresses. A Classic Bundle starts with a buyer-style message and advances after the seller responds. An Alternative Bundle can present marketplace-style content through HTML or PDF and can shorten links through configured shortening services. Initial messages may be loaded from JSON, entered manually, or generated through Elegy's AI integration. Follow-up chains can use scheduled templates or AI Dialog mode, with limits on AI-generated replies before and after link delivery.

QR Design controls the presentation of QR codes that reference the externally generated URL, while Review & Test summarizes readiness for the bundle name, platform, country, service settings, initial message, reply flow, and QR configuration. Elegy can also preview the first email using sample product, seller, price, and URL values before the Bundle is saved.

Figure 5 - QR design and final Bundle review/testing
Figure 5: QR design and final Bundle review/testing

Target Discovery, Outreach, and Reply Management

Elegy’s Statistics dashboard provides an overview of campaign activity across managed Chrome profiles and Gmail accounts. It tracks initial messages, unique seller replies, conversion rates, account status, recent activity, and statistics by browser profile, Gmail account, and targeted marketplace.

Elegy provides both manual and automated seller acquisition. The Send page lets an operator enter a seller email, product title, and price, with optional seller name, product image, and original listing URL. Elegy can automatically select an available Gmail worker or use a specific profile chosen by the operator. The local coordinator assigns the job, the worker sends through an authenticated Gmail session, and Elegy records whether Gmail reports the message as sent.

Operator workflow: statistics, manual outreach
Figure 6: Operator workflow: statistics, manual outreach

The VVS tab automates target discovery through vvsproject.xyz. Searches can be filtered by marketplace, country, price, publication date, delivery availability, category, reviews, and seller activity. Returned records may include seller email and name, product title, price, image, listing URL, marketplace, country, and seller statistics. Elegy validates and deduplicates the records, matches each listing to a compatible Bundle, and queues accepted targets for Gmail outreach.

The Reply tab manages existing conversations. Auto Reply checks unread seller messages, associates each thread with its listing and Bundle, and follows the configured template or AI workflow. Manual Reply works with the currently open Gmail conversation and allows the operator to supply missing listing details, choose a Bundle, or select a particular reply step. The statistics dashboard tracks initial messages, unique replies, conversion rate, account status, and recent activity; History and Logs provide campaign records and technical troubleshooting for Gmail, VVS, the local coordinator, and managed workers.

VVS discovery and reply management
Figure 7: VVS discovery and reply management

AI-Assisted Buyer Conversations

The AI tab contains Elegy's live AI configuration and a testing interface. Operators can configure multiple OpenRouter API keys; the analyzed sample names deepseek/deepseek-v4-flash as its default model. The AI Buyer Test can simulate an interaction using an existing Bundle or custom marketplace, product, price, and seller details.

AI Configuration and Buyer Conversation Testing
Figure 8: AI Configuration and Buyer Conversation Testing

In Classic mode, the AI is instructed to behave as a real marketplace buyer. It uses the listing context and full conversation history to ask natural product questions, maintain a believable buyer persona, and adapt to the seller's replies. 

AI Buyer Impersonation Prompt
Figure 9: AI Buyer Impersonation Prompt

The workflow delays discussion of marketplace delivery until relevant product questions have been answered, discourages pickup or alternative delivery methods, and moves toward the transaction stage only after the seller agrees to marketplace delivery.

AI Marketplace Delivery Negotiation Prompt
Figure 10: AI Marketplace Delivery Negotiation Prompt

A separate classifier evaluates the complete conversation and determines whether the seller has answered the necessary product questions and agreed to marketplace delivery. Elegy marks a conversation ready for link delivery only when agreement is detected with at least 65% confidence. 

In Alternative mode, the AI instead produces marketplace-style notifications stating that the item has been sold, with follow-up messages written in the style of an automated platform notification and the ability to direct the seller toward technical support.

Alternative AI Marketplace Notification Prompt
Figure 11: Alternative AI Marketplace Notification Prompt

Haronrent Backend Integration

Elegy does not implement the seller-facing phishing infrastructure entirely on its own. When a campaign reaches the later transaction stage, the extension authenticates to haronrent.xyz with an operator-supplied API key and uses Haronrent as the external backend for seller-specific transaction content.

The core integration is concentrated in two endpoints. Elegy calls /api/v1/createAd with marketplace, product, price, image, buyer, profile, and related campaign information. The response includes an advertisement identifier and a URL for the generated seller-facing page. Elegy can use that URL directly in Gmail, convert it into a QR code, include it in HTML or PDF content, or use it as part of the configured fallback flow.

If the operator selects a separate mail service first, Elegy calls /api/v1/sendMail with the advertisement identifier, seller email address, and selected mail-service value. This requests delivery of a separate payment or confirmation email before Elegy falls back to sending the link through the buyer conversation. Separating the transactional message from the buyer thread appears intended to make it resemble an automated marketplace or payment notification.

Haronrent: Shared Phishing Infrastructure

Haronrent appears to operate as a commercial phishing-as-a-service platform used by multiple marketplace-fraud operations rather than infrastructure built only for Elegy. The current Haron News / @HaronRent channel shows an active operator platform with workers, teams, profiles, templates, domains, API access, wallets, billing, marketplace chats, and country-specific configurations.

The service advertises a structured commercial model that includes a $350 setup fee, a 6% share of profits, daily payouts, and minimum turnover requirements. Its worker interface also supports separate revenue-sharing percentages, reinforcing a team-based operating model.

Haronrent Telegram advertisement and commercial terms
Figure 12: Haronrent Telegram advertisement and commercial terms

The current Haronrent service shows strong continuity with the Haron_rent phishing ecosystem documented by Imperva in 2024. The present Telegram onboarding uses matching recruitment questions and retains the same worker, profit-sharing, mentor, domain-management, and phishing-page model described in the earlier platform.

Independent documentation for a separate Willhaben fraud-automation bot also lists haronrent.xyz under "Phishing (teams)" and describes phishing delivery after a seller email is collected. Together, the evidence indicates that Haronrent provides reusable phishing infrastructure for multiple fraud tools and operator teams, while Elegy adds automated target discovery, Gmail orchestration, and AI-driven victim interaction on top of that backend.

An Evolution in AI-Enabled Fraud

Elegy v7.3.4 demonstrates how marketplace fraud is evolving from simple phishing messages into coordinated, scalable workflows. The framework automates seller discovery, Gmail communication, campaign management, and AI-driven conversations, using listing context and conversation history to maintain a believable buyer persona and determine when an interaction is ready to progress toward the payment stage.

The investigation also shows that Elegy does not operate in isolation. Rather than implementing all the phishing infrastructure itself, Elegy relies on Haronrent to generate and deliver localized seller-facing phishing content. Haronrent appears to function as reusable phishing-as-a-service infrastructure that can support multiple fraud tools and operator teams.

Together, Elegy and Haronrent illustrate a modular marketplace-fraud ecosystem in which AI-driven social engineering, victim engagement, phishing infrastructure, and delivery services are separated into specialized components. This design can make campaigns more personalized, automated, and scalable while reducing the amount of manual interaction required from operators.

Indicators of Compromise (IOCs)

URLsDescription
hxxps://haronrent[.]xyz/api/v1/getMeValidates the operator-supplied Haronrent API key
hxxps://haronrent[.]xyz/api/v1/createAdSubmits marketplace, product, price, image, buyer, and balance-checker information and returns an advertisement identifier and fraudulent transaction-page URL
hxxps://haronrent[.]xyz/api/v1/sendMailRequests delivery of a separate payment or purchase-confirmation email using the advertisement ID, seller email, and selected mail service
elegy.23-94-145-244.sslip[.]ioElegy Controller and Telemetry Infrastructure
HashDescription
f6bc936104aac9530ede9fa68e08c4639f21737d211fc8d46d17409573f89b65Elegy v7.3.4 Windows launcher
5a434ecdbaafd11673af924f309402dbe67843b278adcf935d6713197b2d261eElegy v7.3.4 Windows launcher

Yara Rule

rule rbrk_Elegy_Launcher

{

    meta:

        description = "Detects Elegy launcher based on embedded API endpoint and strings"

        author = "Rubrik Zero Labs"

        malware = "Elegy v7.3.4"

        date = "2026-09-21"

 

    strings:

        $s1 = "/api/v1/getMe" ascii wide

        $s2 = "/api/v1/createAd" ascii wide

        $s3 = "ELEGY_EXPORT_API" ascii wide

        $s4 = "/api/v1/elegy" ascii wide

        $s5 = "/api/v1/shorten" ascii wide

 

    condition:

        uint16(0) == 0x5A4D and

        all of them

}