VYPR
researchPublished Sep 14, 2026· 1 source

Hundreds of Fake Government Websites Target Central Asian Users in Phishing Scams

Cybercriminals are operating hundreds of fake government and news websites to lure users in Uzbekistan, Belarus, and Tajikistan into phishing scams, aiming to steal money and personal information.

Cybercriminals have established a widespread campaign involving hundreds of fake government and news websites, specifically targeting individuals in Uzbekistan, Belarus, and Tajikistan. These fraudulent sites employ deceptive offers of cash payments or passive income to trick unsuspecting users into divulging sensitive contact information. Researchers at cybersecurity firm F6 have identified over 360 such domains associated with this operation.

The primary objective of these fake websites is to harvest victims' contact details, including names and phone numbers. Once this information is obtained, scammers initiate follow-up contact via phone or email, posing as personal managers or representatives of government programs. They leverage the trust users place in official government initiatives to perpetuate their scams, which ultimately aim to steal money, personal information, or gain unauthorized access to victims' devices.

In Uzbekistan, for instance, the fraudulent sites falsely promise residents substantial weekly payments, amounting to approximately $1,300 USD. The initial step for victims involves providing minimal information, such as their name and phone number. While some sites are simple landing pages, others are more elaborate, mimicking regional news outlets and publishing fabricated stories about government assistance programs before directing users to questionnaires.

Upon submitting their details, victims are contacted by scammers who may request a commission or processing fee to release the promised funds. Alternatively, attackers may attempt to extract more personal data or persuade victims to install what they claim is a necessary application for registration or identity verification. This application, however, is often malware designed to grant attackers control over the victim's device and potentially access their financial accounts.

In some instances, the scammers go as far as requesting scans of victims' passports under the guise of a verification process. These stolen documents can then be misused for further fraudulent activities, such as taking out loans in the victims' names or facilitating more sophisticated phishing attacks. The attackers meticulously replicate the visual style and language of legitimate government portals and news outlets to enhance the credibility of their fake websites.

While F6 has not yet identified the specific threat actor group behind this campaign, the scale of the operation suggests a well-organized criminal enterprise. It remains unclear how many individuals have fallen victim to this elaborate scheme, but the sheer number of fraudulent domains indicates a significant potential reach.

The campaign highlights a persistent tactic of exploiting public trust in government services and social programs. By creating convincing replicas of official resources, cybercriminals can effectively lower users' guard and increase the likelihood of successful phishing and malware deployment. The use of fake news articles and fabricated government offers underscores the evolving sophistication of social engineering tactics in the cybercrime landscape.

This operation serves as a stark reminder for users in the targeted regions, and indeed globally, to exercise extreme caution when encountering unsolicited offers, especially those promising financial windfalls or requiring personal information through unfamiliar websites. Verifying the legitimacy of government programs and official communications through trusted channels is paramount to avoiding such scams.

Synthesized by Vypr AI