This is a follow-up to my post warning about the Celsius Network phishing scam published on April 15th: https://www.publish0x.com/mycryptolife/scam-alert-phishing-attempt-against-celsius-network-xykxdoj
As of May 11th, the scammers have now began to exploit the compromised wallets that they gathered during the phishing attack and are moving funds from the victims wallets into their own wallet. You can see the traffic on etherscan via this link:
https://etherscan.io/address/0xa850345f03be2e6e689f57ac5060f93758716d54
The victims funds are been transferred into this address : 0xa850345f03be2e6e689f57ac5060f93758716d54
and there are some additional interactions over to the following address as well: 0x7d704f039625593233cb7bd0d93c859c02360c09

I do not know exactly what can be done to combat the scammers activity - but for anyone that does know, hopefully this will give you a starting point!