Home/News/Nine-Year Fraud Campaign Clones Russian Company Sites
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Nine-Year Fraud Campaign Clones Russian Company Sites

Nine-Year Fraud Campaign Clones Russian Company Sites

Cybersecurity researchers have detailed a sophisticated, nine-year-long fraud campaign that meticulously clones the websites of major Russian companies to defraud international businesses. The operation, disclosed by Russian cybersecurity vendor F6, targets companies across various sectors, including fertilizer manufacturers and petrochemical companies. Threat actors create exact replicas of legitimate corporate sites to trick international firms into making advance payments for goods or services that are never delivered.

The campaign's longevity, spanning over nine years, highlights the persistent and adaptive nature of the cybercriminals involved. By mimicking the appearance and functionality of well-established Russian enterprises, the fraudsters aim to build trust with potential victims. International companies seeking to procure materials or services from these Russian entities are presented with seemingly authentic online portals. Upon initiating transactions and making advance payments, the funds are diverted to the attackers, while the promised goods or services are never provided. This modus operandi leverages the trust placed in established corporate brands and the complexities of international trade to execute its fraudulent schemes.

F6's analysis indicates that the cloned websites are designed to be highly convincing, often incorporating details that would be present on a genuine corporate site, such as product catalogs, contact information, and even simulated customer testimonials. The attackers likely monitor the online presence and business activities of target Russian companies to ensure the accuracy of their fraudulent replicas. This allows them to respond to inquiries and process payments in a manner that mimics legitimate business operations, thereby increasing the likelihood of successful deception. The ultimate goal is to capture advance payments, which are typically substantial in the industries targeted, such as petrochemicals and fertilizers, where large-scale transactions are common.

The disclosure by F6 serves as a critical warning to international businesses engaging with Russian suppliers. It underscores the importance of rigorous due diligence, including verifying website authenticity through multiple channels beyond just the online presence. This could involve direct communication with known company representatives, cross-referencing information with industry databases, and being wary of requests for upfront payments, especially when dealing with new or unfamiliar suppliers. The campaign's sustained success points to a significant gap in security awareness and verification processes within the international trade ecosystem, particularly when dealing with entities from regions with complex geopolitical or economic landscapes.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next