9-Year Fraud Campaign Clones Russian Company Sites to Steal Payments
Russian cybersecurity vendor F6 has uncovered a sprawling fraud operation that has been cloning the websites of major Russian companies since 2017 to defraud international businesses through fake advance-payment schemes. The threat actors have built lookalike domains impersonating firms across fertilizer manufacturing, petrochemicals, metallurgy, logistics, and banking, copying content directly from legitimate sites and offering versions in English, French, Arabic, and Russian. The campaign has primarily targeted organizations in Commonwealth of Independent States (CIS) countries operating in the B2B and international trade sectors.
The scheme relies on a multi-stage social engineering approach: cold calls, phishing emails, and fraudulent corporate sites are used to initiate contact with potential victims. Once negotiations reach a final stage, unsuspecting sales representatives are instructed to hand the customer off to a "senior manager" — who is actually one of the fraudsters. The attackers then send commercial offers, contracts, and invoices bearing bogus banking details for shell "subsidiary" companies, routing payments to criminal-controlled accounts. One Azerbaijani victim reportedly lost $150,000 in a single fraudulent transaction in April 2025.
F6's investigation identified nearly 100 counterfeit domains linked to the operation, with the earliest registration dating back to 2017. The vast majority of these domains resolve to two IP addresses — 212.127.73[.]235 and 167.86.100[.]68 — and share common DNS records and registration data, indicating a single coordinated campaign. "A significant portion of the infrastructure shares common DNS records, IP addresses, and other registration data, indicating that these websites are part of a single coordinated campaign," said Elena Shamshina, technical lead of F6's Threat Intelligence Department. Security professionals and organizations can use a WHOIS lookup to verify domain ownership and a DNS leak test to audit their own DNS resolution paths for signs of tampering or unauthorized redirection.
The roots of the scheme trace back to 2017, when a Russian chemical company began receiving calls from farmers complaining about delayed deliveries of prepaid fertilizer orders they had never actually placed — exposing the fraudsters' playbook of impersonating legitimate vendors. Businesses engaged in cross-border trade should treat unsolicited prepayment requests as a major red flag and verify counterparties through independent channels. A privacy checkup can also help security teams assess whether their own corporate contact details and executive information have been harvested for use in similar impersonation campaigns.