Top Highlights
- Cybercriminals are extensively using cloned websites and fraudulent documents to impersonate legitimate companies, primarily targeting international B2B trade and siphoning millions through fake transactions.
- The operation involves sophisticated social engineering, including cold calls, phishing emails, and convincing fake contracts, leading to significant financial losses—such as a $150,000 theft in one case.
- The campaign exhibits high levels of technical coordination and replication, with threat actors quickly copying fraud warnings and creating convincing lookalike sites in multiple languages to deceive victims globally.
Threat, Techniques, and Targets
Cybercriminals have run a nine-year fraud scheme by copying websites of major Russian companies, such as fertilizer, petrochemical, metallurgical, logistics, and banking firms. They used lookalike websites with similar content and domain names to trick victims. The fake websites targeted international clients in English, French, Arabic, and Russian.
The attackers used various methods to reach their targets. They contacted companies through cold calls, phishing emails, and fake websites. They also sent fake business documents with false bank details. Sometimes scammers hired sales representatives to make calls and guide the victims to fraudulently sign contracts. Once contact was made, scam artists sent invoices with bogus banking information. Victims then transferred money to accounts controlled by criminals.
Most of the targets are organizations in the Commonwealth of Independent States (CIS). The campaign focused on the B2B sector and international trade. The earliest malicious domain appeared in 2017. The campaign infrastructure includes about 100 fake domains linked to specific IP addresses and sharing common DNS records.
Impact, Implications, and Guidance
This campaign causes financial losses and damages business reputations. Victims have lost large sums, such as one Azerbaijani company losing $150,000. The fake websites and documents create a convincing illusion, making it hard for companies to detect fraud. Fraudsters copy official notices and branding to increase trust.
The attack’s success relies on deception and impersonation. Organizations should be diligent when dealing with international partners. They should verify website domains, check the legitimacy of contact details, and confirm banking information before making payments.
Because of the evolving nature of this scheme, organizations should seek guidance from trusted cybersecurity vendors or authorities for proper remediation strategies. They should always verify business and payment details independently before transferring funds to reduce the risk of fraud.
Stay Ahead with the Latest Tech Trends
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
