Full Report
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies
Analysis Summary
# Incident Report: Nine-Year Brandjacking & B2B Fraud Campaign
## Executive Summary
A large-scale, international fraud campaign has been operating since at least 2017, targeting B2B firms by impersonating major Russian industrial companies. Threat actors utilize sophisticated web cloning, "brandjacking," and social engineering to divert advance payments from international buyers into fraudulent accounts. The campaign has recently expanded its infrastructure to include multi-language support and global top-level domains, resulting in significant financial losses and reputational damage.
## Incident Details
- **Discovery Date:** July 2026 (Public disclosure)
- **Incident Date:** Ongoing since 2017
- **Affected Organization:** Multiple (Impersonated: Fertilizer manufacturers, petrochemical, metallurgical, logistics, and banks)
- **Sector:** B2B Manufacturing, Industrial, and International Trade
- **Geography:** Global (Targeting CIS countries, Azerbaijan, and international firms)
## Timeline of Events
### Initial Access
- **Date/Time:** 2017–Present
- **Vector:** Phishing, Cold Calling, and SEO/Brand Impersonation.
- **Details:** Attackers create high-fidelity clones of legitimate Russian corporate websites. They hire unsuspecting sales reps to make cold calls or use phishing emails to drive traffic to these fake sites.
### Lateral Movement
- **Details:** Not applicable in a traditional network sense; movement occurs through the **business process**. Attackers transition victims from "junior sales reps" (hired decoys) to "senior managers" (fraudsters) to close the deal.
### Data Exfiltration/Impact
- **Details:** Siphoning of advance payments. In one specific instance in April 2025, an Azerbaijani firm lost $150,000. Legitimate brands suffer "brandjacking" where their identity is used to issue fake contracts and invoices.
### Detection & Response
- **How it was discovered:** Russian security vendor F6 identified nearly 100 counterfeit domains sharing infrastructure and IP addresses. Historically, detection occurred when farmers called legitimate companies to complain about missing orders.
- **Response actions taken:** Threat intelligence mapping by F6; public disclosure to warn international B2B partners.
## Attack Methodology
- **Initial Access:** Brandjacking (cloning legitimate websites) and active outreach (phishing/cold calling).
- **Persistence:** Long-term registration of lookalike domains (e.g., .ru, .com, .org).
- **Privilege Escalation:** N/A (Social Engineering).
- **Defense Evasion:** Use of legitimate-looking letterheads, official-sounding aliases, and high-quality web clones to bypass visual scrutiny.
- **Credential Access:** N/A.
- **Discovery:** Scammers perform reconnaissance on legitimate firm catalogs and contact lists to mimic their offerings perfectly.
- **Lateral Movement:** Transitioning communications from public-facing emails to private "senior manager" channels.
- **Collection:** Gathering victim business details to populate fake contracts.
- **Exfiltration:** N/A.
- **Impact:** Financial theft via fraudulent bank account details on "official" invoices.
## Impact Assessment
- **Financial:** Multi-million dollar potential across nine years (Individual loss example: $150,000).
- **Data Breach:** Exposure of victim corporate procurement details and signatures.
- **Operational:** Disruption of supply chains for agricultural and industrial sectors.
- **Reputational:** Severe brand damage to the legitimate Russian firms being impersonated.
## Indicators of Compromise
- **Network Indicators:**
- 212.127.73[.]235
- 167.86.100[.]68
- www.agrocenter-eurohem[.]ru (Historical)
- **File Indicators:** Fraudulent commercial offers, contracts, and invoices on official-looking letterheads.
- **Behavioral Indicators:** Requests for advance payments to "subsidiary" accounts that differ from previous transaction history; contact details on websites that do not match official corporate filings.
## Response Actions
- **Containment:** Monitoring of DNS records for new lookalike domains.
- **Eradication:** Taking down identified fraudulent domains (ongoing).
- **Recovery:** Public advisory to B2B sector to verify banking details via secondary out-of-band channels.
## Lessons Learned
- **Sophisticated Human Layer:** The use of "unprivileged" sales reps who don't know they are working for scammers adds a layer of perceived legitimacy.
- **Verification Gaps:** B2B transactions often lack the automated fraud detection prevalent in B2C banking, allowing large wire transfers to proceed based on spoofed documents.
- **Persistence:** Threat actors are willing to maintain infrastructure for nearly a decade, suggesting high profitability.
## Recommendations
1. **Out-of-Band Verification:** Always verify banking detail changes or new supplier accounts via a known-good phone number or separate communication channel.
2. **Domain Monitoring:** Companies should employ brand protection services to monitor for lookalike domain registrations.
3. **B2B Security Awareness:** Train procurement and sales teams to recognize "brandjacking" and verify the digital certificates/registration of websites before engaging in high-value transactions.
4. **E-Signature Validation:** Use encrypted e-signature platforms that verify the identity of the signer rather than relying on scanned images of signatures.