Nine-Year Fraud Campaign Impersonates Russian Companies to Steal Advance Payments
A sophisticated, nine-year-long fraud campaign has been uncovered, impersonating major Russian companies to trick international businesses into sending advance payments for non-existent goods.

Cybersecurity researchers have detailed a sprawling, nine-year-old fraud campaign that systematically clones the websites of prominent Russian companies to deceive international firms and siphon advance payments. The operation, active since 2017, targets businesses across various sectors, including fertilizer manufacturing, petrochemicals, metallurgy, logistics, and banking, by creating convincing replicas of legitimate company sites.
According to Russian cybersecurity vendor F6, the threat actors meticulously copied content from authentic company websites and often utilized domain names that closely resembled the originals. These fraudulent websites, available in multiple languages including English, French, Arabic, and Russian, were designed to lure international customers into making advance payments for goods that would never be delivered. The scheme primarily focused on organizations within the Commonwealth of Independent States (CIS) countries, particularly in the business-to-business (B2B) sector engaged in international trade.
The attackers employed a multi-pronged approach to initiate contact, including cold calls, phishing emails, and the deceptive corporate websites themselves. In some instances, unsuspecting sales representatives were hired to make cold calls, with instructions to redirect interested customers to a "senior manager" once negotiations progressed. This handover effectively transferred the customer's communication to the fraudsters, who then issued fake commercial offers, contracts, and invoices containing bogus bank details, rerouting payments directly to the criminals.
One documented case involved an Azerbaijani company that reportedly lost $150,000 in April 2025 due to a fraudulent transaction orchestrated through this campaign. F6's investigation has identified nearly 100 counterfeit domains associated with this activity, with the earliest linked domain dating back to 2017. The infrastructure shows common DNS records, IP addresses, and registration data, strongly indicating a single, coordinated campaign.
This modus operandi is not entirely new. A similar scheme surfaced in 2017 when a Russian chemical company received complaints from farmers about undelivered fertilizer orders. Investigations revealed a fraudulent website, "www.agrocenter-eurohem[.]ru," which was a near-exact replica of the legitimate site, with only the bank account details and contact information altered. The attackers even produced convincing commercial proposals on official letterhead, replacing legitimate payment details with their own.
While earlier iterations of the campaign relied heavily on local .ru domains, the more recent fake websites extensively use global top-level domains like .com, .org, and .net. The availability of these sites in multiple languages further broadens their reach to international markets. The attackers have also demonstrated a concerning level of adaptability, even copying and modifying fraud warnings posted by victim companies onto their own fake sites.
F6 researchers also uncovered a comprehensive set of fraudulent business documents, including commercial offers, contracts, and invoices, all containing fake corporate email addresses and banking details. These documents were crafted to appear legitimate, aiming to bolster the victim's confidence in the transaction. The campaign inflicts financial losses on victims and reputational damage on the legitimate companies whose brands are abused.
To mitigate this threat, organizations are advised to exercise extreme due diligence when engaging with business partners, independently verify contact information and payment details before transferring funds, and scrutinize website domain registration dates. Confirming the legitimacy of subsidiaries and contact information through trusted sources and government business registries is also crucial.