Cybersecurity experts have exposed an extensive fraud operation that has been cloning websites of major Russian firms to misappropriate funds from global businesses for over nine years. This sophisticated scheme has targeted international enterprises, utilizing counterfeit sites of Russian corporations across various sectors such as petrochemicals, metallurgy, and banking.
Details of the Fraud Scheme
According to the cybersecurity firm F6, the operation, which dates back to 2017, involves setting up fake websites that closely mimic the legitimate sites of Russian companies. These fraudulent sites target international customers by presenting content in multiple languages, including English, French, Arabic, and Russian. The fraudulent domains often resemble the genuine ones, misleading clients into making advance payments for non-existent goods.
Research shows that the scam primarily focuses on the Commonwealth of Independent States (CIS) countries, exploiting the business-to-business (B2B) sector. The fraudsters initiate contact through cold calls and phishing emails, directing victims to bogus websites where deceptive business documents with false banking details are shared.
Modus Operandi and Impact
The scheme deceives potential customers into engaging with these fake platforms, with altered contact information guiding them to the attackers. Sometimes, unsuspecting sales personnel are hired to conduct cold calls, eventually transferring negotiations to the fraudsters posing as senior managers. This tactic has led to significant financial losses for victims, including an Azerbaijani firm that lost $150,000 in April 2025.
F6’s investigation has identified nearly 100 counterfeit domains, revealing connections to earlier fraud activities. These domains share common DNS records and IP addresses, suggesting a coordinated effort. The campaign’s infrastructure is mainly linked to IP addresses 212.127.73[.]235 and 167.86.100[.]68.
Preventive Measures and Future Outlook
To combat this pervasive threat, businesses are advised to independently verify the authenticity of business partners and their contact information. Checking domain registration details and confirming payment instructions through reliable sources can mitigate such risks. Additionally, companies should be vigilant about verifying the legitimacy of subsidiaries and business documents.
The sophistication of these fraudulent activities, including the replication of fraud warnings, highlights the need for heightened cybersecurity measures. As the campaign continues to evolve, utilizing domains like .com, .org, and .net, vigilance remains crucial for companies engaged in international trade.
Overall, understanding the scale and ingenuity of these fraud schemes can help businesses protect themselves from substantial financial and reputational damage. Staying informed and conducting thorough due diligence are key steps in safeguarding against such cyber threats.
