[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fL4m0nOvKQg6gckLBzKNZmJaj_w_UKSsKvO1KmBd8iuw":3},{"article":4,"iocs":32},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"0260fa08-4dd4-46a8-9634-c09d54973fbf","Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments","nine-year-fraud-campaign-clones-russian-company-sites-to-steal-advance-payments-afe089","Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies","A nine-year fraud campaign has been discovered where threat actors create clone websites of major Russian companies to trick international firms into sending advance payments for non-existent goods. The campaign, active since 2017, uses lookalike domains and copied website content, targeting businesses in CIS countries via cold calls, phishing, and fraudulent corporate websites. Victims are led to believe they are communicating with legitimate companies but are instead routed to fraudsters who provide fake banking details for payments.","Nine-year fraud campaign impersonates Russian companies to steal advance payments.","Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments Ravie LakshmananJul 29, 2026Cybercrime \u002F Threat Intelligence Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The operation has been ongoing since 2017. \"Most of the content on these fraudulent websites was copied from the legitimate company websites. Some also used lookalike domain names,\" the cybersecurity company said in an exclusive report shared with The Hacker News. \"These fake websites, available in English, French, Arabic, and Russian, were used to target international customers and steal advance payments for goods that did not exist.\" Analysis indicates that the phony prepayment scheme has primarily singled out organizations across the Commonwealth of Independent States (CIS) countries with a specific focus on the business-to-business (B2B) sector and international trade via cold calls, phishing email campaigns, and fraudulent corporate websites to initiate contact with potential customers and distribute business documents containing the banking details of fake \"subsidiary\" companies. The scheme works by deceiving potential clients into visiting the replica sites, which have the contact details altered to lead them to the attackers. Select instances have involved the threat actors hiring unsuspecting sales representatives to make cold calls, who are instructed to pass the customer to a \"senior manager\" once the negotiations reach the final stage. From this point onwards, the customer's communications are with the fraudsters, who then send commercial offers, contracts, and invoices with bogus bank details, causing payments to be routed to the criminals. One such victim, an Azerbaijani company, is estimated to have lost $150,000 in April 2025 through a fraudulent transaction. F6's investigation has unearthed nearly 100 counterfeit domains impersonating companies, with links identified between a subset of the infrastructure and prior campaigns. The earliest domain connected to the activity dates back to 2017. The vast majority of the domains are associated with the following IP addresses - 212.127.73[.]235 167.86.100[.]68 \"A significant portion of the infrastructure shares common DNS records, IP addresses, and other registration data, indicating that these websites are part of a single coordinated campaign,\" Elena Shamshina, technical lead of F6's Threat Intelligence Department, said in a statement. The cybersecurity company told The Hacker News that a similar fraudulent scheme unfolded in 2017 when a Russian chemical company began receiving phone calls from farmers about delayed deliveries of prepaid fertilizer orders. The farmers claimed to be in possession of contracts bearing the signatures of individuals who were believed to be company representatives, when, in reality, no such agreements had been signed. Further investigation found evidence of a brandjacking effort where the scammers had created a fraudulent website (\"www.agrocenter-eurohem[.]ru\") that was a near-perfect virtual copy of the legitimate website, with the only changes being the bank account details and contact information. \"The attackers had also produced highly convincing commercial proposals on the company's official letterhead,\" F6 said. \"Although the documents appeared authentic, the payment details had been replaced with accounts controlled by the fraudsters. As a result, unsuspecting customers transferred money for goods that did not exist.\" The campaign is assessed to be international in nature. Although earlier iterations heavily relied on local .ru domains, the newly set up domains make extensive use of .com, .org, and .net top-level domains (TLDs). These websites are available in Russian, English, Arabic, and French. F6 said it also discovered a set of fraudulent business documents mimicking commercial offers, contracts, and invoices containing fake corporate email addresses and fraudulent banking details. \"Analysis of these files indicates that the attackers prepare a complete set of business documentation designed to support the fake transaction and increase the victim's confidence,\" Vera Kolenikova, senior specialist of F6's Cybercrime Investigation Department, said. \"As a result, victims lose money, while the legitimate companies whose brands are abused suffer reputational damage. For businesses engaged in international import and export operations, one of the most effective security measures is to independently verify contact information and payment details before transferring funds.\" Perhaps the most concerning aspect of the campaign is the level of replication involved. After several victim companies published fraud warnings on their official websites, the unknown threat actors wasted no time copying those notices onto their fake counterparts and replaced references to the legitimate domains with fake ones under their control. To mitigate against the threat, organizations are advised to exercise due diligence on business partners using trusted sources and government business registries, ensure the legitimacy of subsidiaries and contact information, check the supplier's website domain and registration date, and confirm payment details before transferring funds. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Brand Impersonation, Cybercrime, Domain Security, email security, online fraud, Payment Fraud, Phishing, Social Engineering, Threat Intelligence, Web Security ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See","https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fnine-year-fraud-campaign.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhD9hThKkBhl022O0TklhaF1JKxLj1RKJjnUgfHzzyuxctFOR0UIyUS0FH1No7KlXJHHmQwUKafQf0UYDm0g6v5RU0m1VS-7v-NtgBCW0OXsPhVeX-IAnluUD-FpMoyTc-wrN55GFssISEWcfJNhBPywn7Pp35cww_lLDZdrWxEqpGWgC15vSK_N4Qo1eM\u002Fs1600\u002Frussian-hacking.jpg","2026-07-29T13:42:57+00:00","2026-07-29T16:00:13.60676+00:00",7,[18,21],{"name":19,"type":20},"F6","vendor",{"name":22,"type":23},"Nine-Year Fraud Campaign","campaign","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":24,"icon":26,"name":27,"slug":28},null,"Threat Intelligence","threat-intelligence",[30],{"category":31},{"id":24,"icon":26,"name":27,"slug":28},[33,37,39],{"type":34,"value":35,"context":36},"ip","212.127.73.235","IP address associated with counterfeit domains.",{"type":34,"value":38,"context":36},"167.86.100.68",{"type":40,"value":41,"context":42},"domain","www.agrocenter-eurohem.ru","Example of a counterfeit domain used in the campaign."]