Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments — Threadlinqs Intelligence
As of 2026-07-29, Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments is a medium-severity fraud threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-1765 · Severity: MEDIUM · Status: ACTIVE · Category: FRAUD
A prepayment/advance-fee fraud operation active since 2017 has built nearly 100 lookalike websites cloning legitimate Russian fertilizer, petrochemical, metallurgical, logistics, and banking
Since at least 2017, an unattributed, financially motivated fraud operation has built and maintained a large lookalike-website infrastructure impersonating major Russian companies across fertilizer manufacturing, petrochemicals, metallurgy, logistics, and banking. F6's Threat Intelligence Department (technical lead Elena Shamshina, with Vera Kolenikova of F6's Cybercrime Investigation Department) identified nearly 100 counterfeit domains tied to the operation. Most sites copy the full content, branding, and layout of the legitimate companies they impersonate, sometimes on exact domain names and sometimes on lookalike/typosquat variants (e.g., 'www.agrocenter-eurohem.ru', the earliest domain linked to the campaign, dating to 2017). Early-era sites relied heavily on .ru domains; more recent infrastructure has shifted toward .com, .org, and .net TLDs to appear more internationally credible, and the clone sites are served in Russian, English, Arabic, and French to reach international buyers across multiple regions.
The operation is not a technical exploit — there is no CVE, malware, or software vulnerability involved. Instead, operators combine the cloned websites with cold-calling by hired sales representatives and targeted phishing outreach to initiate contact with prospective international B2B buyers, typically importers of Russian commodities. Once contact is established, victims are sent a complete package of forged business documentation — commercial offers, contracts, and invoices reproduced on what appears to be the legitimate company's official letterhead, using fake corporate email addresses. The documents are visually convincing; the only substantive alteration is that banking/payment details are replaced with accounts controlled by the fraud operators. Victims wire advance/prepayment funds for goods (e.g., fertilizer or metals shipments) that are never delivered.
F6 assessed that a significant portion of the fraud infrastructure shares common DNS records, hosting IP addresses (including 212.127.73.235 and 167.86.100.68), and domain-registration data, indicating the nearly 100 sites are operated by a single coordinated group rather than disparate copy-cat actors. F6 further identified links between a subset of the infrastructure and prior fraud campaigns run by the same operators, indicating a persistent, evolving operation that has been iterating on its domain portfolio and tooling for close to a decade rather than a one-off scheme.
F6's disclosure identifies the Commonwealth of Independent States (CIS) as the primary geographic focus of the scheme, with the B2B sector and international trade specifically singled out; cold calls, phishing email campaigns, and the fraudulent corporate websites are used in combination to initiate contact within that focus region before expanding to other international buyers. F6 Cybercrime Investigation Department senior specialist Vera Kolenikova stated that analysis of the seized/observed forged files indicates the attackers prepare complete business documentation packages specifically to support fake transactions and increase victim confidence, rather than sending a single forged document in isolation. F6 also documented a defense-evasion behavior in which, after legitimate companies or partners posted public fraud warnings referencing the impersonators, the operators copied those warning notices onto their own fraudulent sites but replaced the referenced domain names — using the appearance of a legitimate anti-fraud notice to redirect victim suspicion away from the actual fraudulent domain being used against them. The clearest documented financial-impact case is an Azerbaijani company that lost $150,000 in April 2025 after transacting with cloned-site operators believing them to be a legitimate Russian supplier. Because the scheme relies entirely on social engineering and document forgery rather than a technical vulnerability, there is no patch; F6's guidance to prospective intern
Target sectors: fertilizer manufacturing, petrochemicals, metallurgy, logistics, banking financial services, international b2b trade import-export
Target regions: Commonwealth of Independent States (CIS) — primary geographic focus per F6, azerbaijan, Middle East / North Africa (Arabic-language clone sites), Francophone markets (French-language clone sites), International B2B trade partners of Russian exporters (global)
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
FRAUD, MEDIUM, threat intelligence, cybersecurity, T1594, T1598.003, T1589.002, T1591.002, T1583.001, T1583.006, T1585.002, T1608.005, T1583.004, T1566.001