Cybersecurity researchers at Russian security company F6 have disclosed details of a large scale fraud campaign that has been operating since 2017 by creating counterfeit versions of well known Russian company websites to deceive international businesses into making advance payments for goods that do not exist. According to the company, the operation has targeted organizations for more than nine years by impersonating fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The fraudulent websites closely resemble legitimate corporate sites, with most of the content copied directly from the original pages while altering key details such as contact information and banking credentials. F6 reported that many of the fake websites use lookalike domain names and are available in English, French, Arabic, and Russian to reach international customers involved in cross border trade.
The investigation found that the fraud campaign has primarily targeted organizations across Commonwealth of Independent States countries, with a particular focus on business to business transactions and international trade. Threat actors reportedly initiate contact through cold calls, phishing email campaigns, and fraudulent corporate websites before distributing business documents that include the banking details of fake subsidiary companies. Victims are directed to replica websites where the contact information has been modified to connect them with the attackers instead of the legitimate businesses. In some cases, the criminals hired unsuspecting sales representatives to make initial calls to potential customers. Once negotiations reached the final stages, the representatives transferred communications to a supposed senior manager, who was actually part of the fraud operation. The attackers then issued commercial offers, contracts, and invoices containing fraudulent bank account details, causing victims to transfer funds directly to criminal controlled accounts. F6 cited one incident involving an Azerbaijani company that reportedly lost approximately 150,000 dollars through a fraudulent payment made in April 2025.
Researchers identified nearly 100 counterfeit domains linked to the operation and found connections between sections of the infrastructure and previous fraud campaigns dating back to 2017. According to F6, much of the infrastructure shares common DNS records, IP addresses, and registration information, indicating that it is part of one coordinated campaign. Technical Lead of F6 Threat Intelligence Department, Elena Shamshina, stated that the shared infrastructure strongly suggests centralized management of the fraudulent websites. The investigation also uncovered evidence connected to an earlier incident in 2017 involving a Russian chemical company that received complaints from farmers about delayed deliveries after they had prepaid for fertilizer orders. Further examination revealed that criminals had created an almost identical copy of the company’s official website using a fraudulent domain while replacing only the contact details and payment information. F6 stated that the attackers also produced convincing commercial proposals using official company letterheads, with fraudulent banking details replacing legitimate payment information, leading customers to pay for products that were never delivered.
F6 assessed the operation as international in scope, noting that while earlier stages mainly relied on local .ru domains, more recent activity has shifted toward .com, .org, and .net top level domains to broaden its reach. Researchers also discovered fraudulent commercial offers, contracts, and invoices containing fake corporate email addresses and manipulated banking details that were designed to make transactions appear legitimate. According to Senior Specialist Vera Kolenikova from F6 Cybercrime Investigation Department, the documentation demonstrates that attackers prepare complete business packages to increase the confidence of potential victims. One of the more concerning findings was that after legitimate companies published fraud warnings on their official websites, the attackers quickly copied those notices onto the counterfeit websites while replacing references to genuine domains with fake ones under their control. To reduce the risk of falling victim to similar schemes, F6 advised organizations engaged in international trade to independently verify business partners through trusted sources and official government business registries, confirm subsidiary information and contact details, review website domains and registration dates, and carefully verify payment information before transferring funds.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.