AI Security AI安全 6h ago Updated 2h ago 更新于 2小时前 48

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments 九年诈骗活动克隆俄罗斯公司网站以骗取预付款

A nine-year fraud campaign (active since 2017) involves cloning websites of major Russian companies to steal advance payments from international B2B clients. Attackers use lookalike domains, multilingual fake sites (English, French, Arabic, Russian), and forged business documents with altered banking details to deceive victims. The campaign targets CIS countries and global trade sectors including fertilizer, petrochemicals, metallurgy, logistics, and banking via cold calls, phishing emails, and 一个持续九年的大规模诈骗活动,通过克隆俄罗斯主要公司的网站来骗取国际公司的预付款。 诈骗者创建了化肥制造商、石化公司、冶金厂、物流运营商和银行的仿冒网站,使用相似域名和多语言内容 targeting 国际客户。 该活动主要通过冷电话、钓鱼邮件和虚假企业网站接触潜在客户,分发包含虚假子公司银行信息的商业文件。 F6 发现近 100 个假冒域名,共享常见 DNS 记录、IP 地址和注册数据,表明这是一个协调一致的活动。 受害者包括一家阿塞拜疆公司,2025 年 4 月损失约 15 万美元;合法公司品牌被滥用,遭受声誉损害。

75
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • A nine-year fraud campaign (active since 2017) involves cloning websites of major Russian companies to steal advance payments from international B2B clients.
  • Attackers use lookalike domains, multilingual fake sites (English, French, Arabic, Russian), and forged business documents with altered banking details to deceive victims.
  • The campaign targets CIS countries and global trade sectors including fertilizer, petrochemicals, metallurgy, logistics, and banking via cold calls, phishing emails, and replica corporate sites.
  • Nearly 100 counterfeit domains were identified, many sharing infrastructure (IP addresses, DNS records), indicating a coordinated operation.
  • Victims include an Azerbaijani company that lost $150,000 in April 2025; legitimate brands suffer reputational damage while attackers profit from non-existent goods.

Why It Matters

This case exemplifies sophisticated, long-running brand impersonation attacks that exploit trust in established corporate identities—critical for AI practitioners developing fraud detection systems, cybersecurity tools, or natural language processing models trained on deceptive content. The scale and persistence of the campaign highlight the need for advanced anomaly detection in domain registration patterns, document authenticity verification, and behavioral analysis in B2B communication flows. For industry stakeholders, it underscores the growing threat landscape where cybercriminals mimic legitimate operations at near-perfect fidelity, demanding proactive digital identity protection and cross-border collaboration.

Technical Details

  • Domain Cloning Strategy: Fraudsters register visually similar domains (e.g., agrocenter-eurohem.ru vs. legitimate site) and replicate entire website structures, including layout, content, and even fraud warning notices posted by victims.
  • Multilingual Deception: Fake websites are localized into four languages (Russian, English, Arabic, French) to broaden appeal across international markets, particularly targeting non-Russian-speaking businesses.
  • Document Forgery: Attackers generate realistic commercial offers, contracts, and invoices using official letterheads but substitute bank account numbers with those controlled by criminals; these files are distributed via phishing or cold call follow-ups.
  • Infrastructure Sharing: Analysis reveals overlapping IP addresses (212.127.73.235, 167.86.100.68) and shared DNS records among nearly 100 fraudulent domains, suggesting centralized control and operational cohesion.
  • Evolution Over Time: Early campaigns used only .ru domains; newer iterations increasingly adopt global TLDs (.com, .org, .net) to appear more credible to international audiences and evade regional filtering.

Industry Insight

Organizations engaged in international trade must implement mandatory dual-channel verification protocols—confirming payment details through both written documentation and direct phone contact with known representatives—to prevent wire fraud stemming from cloned sites or forged letters. Security teams should deploy automated monitoring solutions that scan for newly registered domains mimicking their brand’s URL structure, especially those with recent creation dates hosting HTTPS-enabled pages resembling official portals. Additionally, AI-driven email security platforms should be enhanced with contextual analysis capabilities to detect subtle inconsistencies in sender behavior, such as mismatched corporate signatures or unusual attachment types linked to financial transactions, thereby reducing reliance on static signature-based filters alone.

TL;DR

  • 一个持续九年的大规模诈骗活动,通过克隆俄罗斯主要公司的网站来骗取国际公司的预付款。
  • 诈骗者创建了化肥制造商、石化公司、冶金厂、物流运营商和银行的仿冒网站,使用相似域名和多语言内容 targeting 国际客户。
  • 该活动主要通过冷电话、钓鱼邮件和虚假企业网站接触潜在客户,分发包含虚假子公司银行信息的商业文件。
  • F6 发现近 100 个假冒域名,共享常见 DNS 记录、IP 地址和注册数据,表明这是一个协调一致的活动。
  • 受害者包括一家阿塞拜疆公司,2025 年 4 月损失约 15 万美元;合法公司品牌被滥用,遭受声誉损害。

为什么值得看

这篇文章揭示了针对 B2B 和国际贸易的复杂网络欺诈手段,对从事跨境业务的企业具有重要警示意义。它展示了攻击者如何利用品牌仿冒和社会工程学进行长期、有组织的诈骗,提醒行业加强身份验证和尽职调查流程。

技术解析

  • 品牌仿冒(Brandjacking):攻击者创建与真实网站几乎一模一样的克隆站点,仅修改银行账户信息和联系方式,甚至复制官方信头制作商业提案、合同和发票。
  • 多语言伪装:伪造网站提供英语、法语、阿拉伯语和俄语版本,面向 CIS 国家及国际市场客户,增强可信度。
  • 基础设施复用:多个假冒域名共享相同 IP 地址(如 212.127.73[.]235, 167.86.100[.]68)和 DNS 记录,表明背后存在统一控制的基础设施。
  • 社会工程链:结合冷呼叫、钓鱼邮件、“高级经理”话术转移客户注意力,最终引导至虚假页面完成支付指令替换。
  • 动态响应机制:当真实公司发布欺诈警告后,攻击者迅速在仿站中同步更新内容,并将指向真实域名的链接替换为自身控制的域名。

行业启示

  • 强化第三方验证机制:企业在进行大额预付交易前,必须通过独立渠道核实供应商身份、子公司资质及银行账户信息,避免仅依赖对方提供的文档或网站。
  • 建立数字品牌监控体系:主动扫描市场上是否存在与其品牌相似的恶意域名或仿冒网站,尤其关注 .com/.org/.net 等通用 TLD 下的新注册站点。
  • 提升员工与社会工程对抗能力:定期开展反钓鱼培训,特别是对销售、财务等易受攻击岗位人员,使其能识别异常沟通路径和可疑商业文件特征。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全