Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
A nine-year fraud campaign (active since 2017) involves cloning websites of major Russian companies to steal advance payments from international B2B clients. Attackers use lookalike domains, multilingual fake sites (English, French, Arabic, Russian), and forged business documents with altered banking details to deceive victims. The campaign targets CIS countries and global trade sectors including fertilizer, petrochemicals, metallurgy, logistics, and banking via cold calls, phishing emails, and
Analysis
TL;DR
- A nine-year fraud campaign (active since 2017) involves cloning websites of major Russian companies to steal advance payments from international B2B clients.
- Attackers use lookalike domains, multilingual fake sites (English, French, Arabic, Russian), and forged business documents with altered banking details to deceive victims.
- The campaign targets CIS countries and global trade sectors including fertilizer, petrochemicals, metallurgy, logistics, and banking via cold calls, phishing emails, and replica corporate sites.
- Nearly 100 counterfeit domains were identified, many sharing infrastructure (IP addresses, DNS records), indicating a coordinated operation.
- Victims include an Azerbaijani company that lost $150,000 in April 2025; legitimate brands suffer reputational damage while attackers profit from non-existent goods.
Why It Matters
This case exemplifies sophisticated, long-running brand impersonation attacks that exploit trust in established corporate identities—critical for AI practitioners developing fraud detection systems, cybersecurity tools, or natural language processing models trained on deceptive content. The scale and persistence of the campaign highlight the need for advanced anomaly detection in domain registration patterns, document authenticity verification, and behavioral analysis in B2B communication flows. For industry stakeholders, it underscores the growing threat landscape where cybercriminals mimic legitimate operations at near-perfect fidelity, demanding proactive digital identity protection and cross-border collaboration.
Technical Details
- Domain Cloning Strategy: Fraudsters register visually similar domains (e.g., agrocenter-eurohem.ru vs. legitimate site) and replicate entire website structures, including layout, content, and even fraud warning notices posted by victims.
- Multilingual Deception: Fake websites are localized into four languages (Russian, English, Arabic, French) to broaden appeal across international markets, particularly targeting non-Russian-speaking businesses.
- Document Forgery: Attackers generate realistic commercial offers, contracts, and invoices using official letterheads but substitute bank account numbers with those controlled by criminals; these files are distributed via phishing or cold call follow-ups.
- Infrastructure Sharing: Analysis reveals overlapping IP addresses (212.127.73.235, 167.86.100.68) and shared DNS records among nearly 100 fraudulent domains, suggesting centralized control and operational cohesion.
- Evolution Over Time: Early campaigns used only .ru domains; newer iterations increasingly adopt global TLDs (.com, .org, .net) to appear more credible to international audiences and evade regional filtering.
Industry Insight
Organizations engaged in international trade must implement mandatory dual-channel verification protocols—confirming payment details through both written documentation and direct phone contact with known representatives—to prevent wire fraud stemming from cloned sites or forged letters. Security teams should deploy automated monitoring solutions that scan for newly registered domains mimicking their brand’s URL structure, especially those with recent creation dates hosting HTTPS-enabled pages resembling official portals. Additionally, AI-driven email security platforms should be enhanced with contextual analysis capabilities to detect subtle inconsistencies in sender behavior, such as mismatched corporate signatures or unusual attachment types linked to financial transactions, thereby reducing reliance on static signature-based filters alone.
Disclaimer: The above content is generated by AI and is for reference only.