hacker-news · Crawled Jul 29, 2026

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

3 IoCs
Read original article ↗

AI Summary

A long-running cybercrime campaign has been active since 2017, involving the creation of fake websites that clone legitimate Russian companies in sectors such as fertilizer, petrochemicals, and logistics. The threat actors use lookalike domains and cloned content in multiple languages to deceive international B2B customers into making advance payments for non-existent goods. Victims are contacted via cold calls and phishing emails, and are provided with forged contracts and invoices containing fraudulent banking details. The operation has been linked to at least 100 counterfeit domains and shows signs of coordination through shared infrastructure and replication of fraud warnings on fake sites.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
IP 212[.]127[.]73[.]235 Details →
IP 167[.]86[.]100[.]68 Details →
Domain www[.]agrocenter-eurohem[.]ru Details →