CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

July 29, 2026

Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies to siphon funds from international firms for over nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The operation has been ongoing since 2017.

Most of the content on these fraudulent websites was copied from legitimate company websites, with some using lookalike domain names. These fake websites, available in English, French, Arabic, and Russian, were used to target international customers and steal advance payments for goods that did not exist.

The phony prepayment scheme has primarily singled out organizations across CIS countries, focusing on the B2B sector and international trade via cold calls, phishing email campaigns, and fraudulent corporate websites. The scheme deceives potential clients into visiting replica sites with altered contact details. In some instances, the threat actors hired unsuspecting sales representatives to make cold calls, who then passed customers to a ‘senior manager’ (the fraudster) for final negotiations. The fraudsters then sent commercial offers, contracts, and invoices with bogus bank details, routing payments to criminals.

One victim, an Azerbaijani company, lost $150,000 in April 2025. F6 investigation unearthed nearly 100 counterfeit domains impersonating companies, with links to prior campaigns. The earliest domain dates back to 2017. A significant portion of the infrastructure shares common DNS records, IP addresses, and registration data, indicating a single coordinated campaign.

To mitigate against the threat, organizations are advised to exercise due diligence on business partners using trusted sources and government business registries, ensure the legitimacy of subsidiaries and contact information, check the supplier’s website domain and registration date, and confirm payment details before transferring funds.

CVEs: CVE-2026-50522

Companies: F6