Skip to main content
Emerging Threats

Russian Firms Targeted in Nine-Year Advance Payment Fraud Campaign

Businessperson's desk with laptop and papers, surrounded by documents, in a modern office with natural daylight.

Nearly 100 counterfeit domains, some tracing back to 2017, have been used to impersonate major Russian companies and siphon advance payments from international business partners, researchers at Russian cybersecurity vendor F6 told The Hacker News.

Scope: sectors targeted, languages used, and a nine‑year timeline

F6's investigation describes a long‑running, large‑scale fraud campaign that has impersonated companies across fertilizer manufacturing, petrochemicals, metallurgy, logistics and banking. The operation, the vendor says, has been active since 2017 and includes "nearly 100 counterfeit domains" available in Russian, English, Arabic and French. Earlier iterations relied heavily on .ru domains; more recent sites increasingly use .com, .org and .net top‑level domains.

Tactics: cloned websites, fake subsidiaries, hired sales representatives

"Most of the content on these fraudulent websites was copied from the legitimate company websites. Some also used lookalike domain names," F6 wrote in its report to The Hacker News. The attackers reproduced official pages and business documents, altered contact details and bank accounts, and used multiple outreach channels — cold calls, phishing emails and fraudulent corporate sites — to engage targets.

In several instances the campaign employed unwitting intermediaries: recruiters or sales representatives who made initial cold calls and then passed interested customers to a "senior manager" controlled by the fraudsters. From that point the victims received commercial offers, contracts and invoices containing bogus banking details that routed prepayments to criminal accounts.

Case examples: brandjacking, forged contracts, and a six‑figure loss

F6 recounts a 2017 episode in which farmers contacted a Russian chemical company about delayed prepaid fertilizer deliveries. Those farmers held contracts "bearing the signatures of individuals who were believed to be company representatives," but no genuine agreements had been signed. Investigators found a near‑perfect fake website — "www.agrocenter‑eurohem[.]ru" — that mirrored the legitimate site except for bank and contact details, and attackers had produced convincing commercial proposals on official letterhead with payment details replaced.

F6 also cites a recent financial hit: an Azerbaijani company that is estimated to have lost $150,000 in April 2025 after transferring funds to accounts listed on fraudulent documentation. "As a result, victims lose money, while the legitimate companies whose brands are abused suffer reputational damage," the report noted.

Infrastructure clues: shared DNS, repeat IP addresses, and links to prior campaigns

Analysis shows a "significant portion of the infrastructure shares common DNS records, IP addresses, and other registration data, indicating that these websites are part of a single coordinated campaign," Elena Shamshina, technical lead of F6's Threat Intelligence Department, said in a statement. F6 identified two IP addresses associated with the majority of the domains: 212.127.73[.]235 and 167.86.100[.]68. The vendor also found links between a subset of the infrastructure and prior fraudulent campaigns.

What this means for technologists, procurement teams, and the legitimate companies whose brands are copied

  • Technologists and security teams: expect active brandjacking and rapid replication of defensive content. F6 reports attackers copied official fraud warnings from legitimate sites and replaced references to real domains with fake ones, indicating the threat actors monitor and update their forgeries to mirror public disclosures.
  • Procurement and finance teams at import/export companies: verify contact information and payment details before transferring funds. F6 explicitly recommends using trusted sources and government business registries, checking supplier domain names and registration dates, and confirming subsidiary legitimacy and contact details.
  • Legitimate companies whose brands are abused: anticipate reputational damage and the need to monitor both domain registrations and public warnings. According to F6, attackers prepare a "complete set of business documentation designed to support the fake transaction and increase the victim's confidence," raising the bar for detection by customers.

Practical mitigation steps drawn from the report

F6's investigators stress basic but specific due diligence measures: independently verify contact and payment information using trusted channels and government registries; confirm the legitimacy of subsidiaries and any altered contact details; check the supplier's website domain and registration date; and require secondary confirmation of payment instructions before funds move. Those steps are presented as especially important for businesses engaged in international import and export operations.

The campaign's longevity, multilingual reach and tendency to copy defensive notices onto fake sites make it a resilient, adaptive fraud model. Defenders and buyers can take concrete verification steps now; whether those checks will stay ahead of attackers who clone warnings as quickly as they clone corporate pages is the practical question left by F6's findings.

Read the original report: The Hacker News — Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments