Ethical Hacking News
A nine-year-long operation involving the cloning of Russian company sites has been uncovered by cybersecurity researchers, resulting in significant financial losses for international firms.
A nine-year-long operation involving the cloning of Russian company sites to steal advance payments from international firms has been uncovered. The scam involved creating lookalike websites of major Russian companies to deceive potential clients into visiting replica sites. The threat actors targeted organizations across CIS countries with a focus on the B2B sector and international trade. The operation involved nearly 100 counterfeit domains impersonating companies in various industries. Azerbaijani company lost $150,000 in April 2025 through a fraudulent transaction involving brandjacking and fake business documentation. The threat actors used a set of fraudulent business documents that mimicked commercial offers, contracts, and invoices. Organizations are advised to exercise due diligence on business partners, ensure legitimacy of subsidiaries and contact information, and confirm payment details before transferring funds.
The world of cybersecurity has witnessed numerous scams and fraudulent operations, but a recent case stands out for its sheer scale and complexity. A nine-year-long operation involving the cloning of Russian company sites to steal advance payments from international firms has been uncovered by cybersecurity researchers. The operation, which began in 2017, is believed to have targeted organizations across the Commonwealth of Independent States (CIS) countries with a focus on the business-to-business (B2B) sector and international trade.
The scam, which involved creating lookalike websites of major Russian companies, was designed to deceive potential clients into visiting the replica sites. These websites were tailored to appear as legitimate versions of their counterparts, complete with altered contact details that led unsuspecting customers to the attackers. The threat actors would then send commercial offers, contracts, and invoices with bogus bank details, causing payments to be routed to the criminals.
According to Russian cybersecurity vendor F6, the threat actors set up nearly 100 counterfeit domains impersonating companies across fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The operation was so extensive that it involved hiring unsuspecting sales representatives to make cold calls, who were instructed to pass customers to a "senior manager" once negotiations reached the final stage.
One such victim, an Azerbaijani company, is estimated to have lost $150,000 in April 2025 through a fraudulent transaction. The attack on this firm involved the use of a brandjacking effort where scammers had created a fraudulent website that was a near-perfect virtual copy of the legitimate website, with the only changes being the bank account details and contact information.
F6 discovered that the threat actors also prepared a complete set of business documentation designed to support the fake transaction and increase the victim's confidence. This included commercial offers, contracts, and invoices containing fake corporate email addresses and fraudulent banking details.
The campaign is assessed to be international in nature, with earlier iterations relying heavily on local .ru domains but now using .com, .org, and .net top-level domains (TLDs). These websites are available in Russian, English, Arabic, and French. The threat actors also used a set of fraudulent business documents that mimicked commercial offers, contracts, and invoices.
The level of replication involved in this operation is concerning, with the attackers wasting no time copying the fraud warnings posted on legitimate websites onto their fake counterparts. This has raised concerns among cybersecurity experts about the ease with which these scammers can adapt to new security measures.
To mitigate against this threat, organizations are advised to exercise due diligence on business partners using trusted sources and government business registries, ensure the legitimacy of subsidiaries and contact information, check the supplier's website domain and registration date, and confirm payment details before transferring funds. By following these steps, businesses can reduce their risk of falling victim to this extensive scam.
In conclusion, this nine-year operation highlights the need for cybersecurity awareness among international firms. The cloning of company sites to steal advance payments is a sophisticated tactic that requires vigilance from both businesses and regulators. As new scams emerge, it is essential that we stay informed about these threats and take proactive steps to protect ourselves.
Related Information:
https://www.ethicalhackingnews.com/articles/A-Nine-Year-Operation-of-Deception-The-Extensive-Clone-Site-Scam-Targeting-International-Businesses-ehn.shtml
https://thehackernews.com/2026/07/nine-year-fraud-campaign.html
Published: Wed Jul 29 09:44:57 2026 by llama3.2 3B Q4_K_M