Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years.
Intelligence analysis by Llama

A nine-year fraud campaign has been uncovered, where threat actors create clone websites of Russian companies to steal advance payments from international firms. The operation has been ongoing since 2017, with the attackers using lookalike domain names and fake websites to target international customers.
Imagine you're a business owner, and someone calls you claiming to be from a company you've worked with before. They offer you a deal that sounds too good to be true, and they ask you to pay them in advance. But when you try to contact the company, you realize that the person on the phone was actually a scammer. This is what's happening in a nine-year fraud campaign where scammers create fake websites and contact information to steal money from businesses.
Analysis
A Nine-Year Scam Unfolds
The cybersecurity researchers at F6 have uncovered a large-scale fraud campaign that has been ongoing since 2017. The threat actors have created clone websites of major Russian companies, including fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. These fake websites are designed to target international customers and steal advance payments for goods that do not exist.
The operation is assessed to be international in nature, with the attackers using a range of top-level domains, including .com, .org, and .net. The websites are available in Russian, English, Arabic, and French, making it easier for the attackers to target a wider range of victims.
Analysis of the campaign suggests that the attackers use a range of tactics to deceive their victims. These include creating highly convincing commercial proposals on the company's official letterhead, using fake corporate email addresses and fraudulent banking details. The attackers also prepare a complete set of business documentation designed to support the fake transaction and increase the victim's confidence.
One of the most concerning aspects of the campaign is the level of replication involved. After several victim companies published fraud warnings on their official websites, the unknown threat actors wasted no time copying those notices onto their fake counterparts and replaced references to the legitimate domains with fake ones under their control.
To mitigate against the threat, organizations are advised to exercise due diligence on business partners using trusted sources and government business registries, ensure the legitimacy of subsidiaries and contact information, check the supplier's website domain and registration date, and confirm payment details before transferring funds.
A Pattern of Deception
The campaign is a classic example of a brandjacking effort, where the attackers create a fraudulent website that is a near-perfect virtual copy of the legitimate website. The only changes are the bank account details and contact information, which are replaced with accounts controlled by the fraudsters.
The attackers have also produced highly convincing commercial proposals on the company's official letterhead, which are designed to increase the victim's confidence in the transaction. The use of fake corporate email addresses and fraudulent banking details makes it difficult for victims to detect the scam.
The Road Ahead
The discovery of this campaign highlights the ongoing threat of large-scale fraud campaigns that can have significant financial consequences for international businesses. The use of clone websites and fake payment details makes it difficult for victims to detect the scam, and the fact that this operation has been ongoing for nine years suggests a high level of sophistication and organization.
Organizations are advised to exercise due diligence on business partners using trusted sources and government business registries, ensure the legitimacy of subsidiaries and contact information, check the supplier's website domain and registration date, and confirm payment details before transferring funds.
Key points
- A nine-year fraud campaign has been uncovered, where threat actors create clone websites of Russian companies to steal advance payments from international firms.
- The operation has been ongoing since 2017, with the attackers using lookalike domain names and fake websites to target international customers.
- The scammers use a range of tactics to deceive their victims, including creating highly convincing commercial proposals and using fake corporate email addresses and fraudulent banking details.
- Organizations are advised to exercise due diligence on business partners using trusted sources and government business registries, ensure the legitimacy of subsidiaries and contact information, check the supplier's website domain and registration date, and confirm payment deta…
If this development plays out positively, businesses may become more vigilant in verifying contact information and payment details before transferring funds. This could lead to a reduction in the number of successful scams and a decrease in financial losses for international businesses.
If the scammers continue to adapt and improve their tactics, the number of successful scams could increase, leading to significant financial losses for international businesses. Additionally, the fact that this operation has been ongoing for nine years suggests a high level of sophistication and organization, making it difficult for victims to detect the scam.



