Sophisticated 'Brandjacking' Campaign Targets International Firms with Fake Russian Company Websites
A long-running, large-scale fraud campaign has been uncovered, meticulously impersonating major Russian companies to defraud international firms of advance payments. Threat actors have created nearly 100 lookalike websites, complete with convincing business documentation, siphoning funds for over nine years from unsuspecting B2B clients.
Cybersecurity researchers have unveiled details of an extensive fraud operation involving the creation of highly convincing replica websites of prominent Russian companies. This sophisticated "brandjacking" campaign has been actively siphoning funds from international firms for more than nine years.
According to Russian cybersecurity vendor **F6**, the threat actors have established clone websites for various sectors, including fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The operation dates back to at least 2017.
"Most of the content on these fraudulent websites was copied from the legitimate company websites. Some also used lookalike domain names," **F6** stated in an exclusive report. "These fake websites, available in English, French, Arabic, and Russian, were used to target international customers and steal advance payments for goods that did not exist."

### Modus Operandi: Deception at Scale
The phony prepayment scheme has primarily targeted organizations within the Commonwealth of Independent States (**CIS**) countries, focusing heavily on the business-to-business (**B2B**) sector and international trade. Attackers initiate contact through cold calls, phishing email campaigns, and the fraudulent corporate websites themselves. These interactions lead to the distribution of business documents containing banking details for fake "subsidiary" companies.
The scheme works by tricking potential clients into visiting the replica sites, where contact details have been altered to redirect communications to the attackers. In some instances, the threat actors even hired unsuspecting sales representatives for cold calls, instructing them to transfer customers to a "senior manager" once negotiations reached a critical stage.
From that point, all customer communications are with the fraudsters, who then send commercial offers, contracts, and invoices with bogus bank details. This ensures payments are routed directly to the criminals. One Azerbaijani company reportedly lost $150,000 in April 2024 due to a fraudulent transaction.
### Uncovering the Infrastructure
**F6**'s investigation has uncovered nearly 100 counterfeit domains impersonating legitimate companies. Links have been identified between a subset of this infrastructure and prior campaigns, with the earliest associated domain dating back to 2017. The vast majority of these domains are linked to the following IP addresses:
* 212.127.73[.]235
* 167.86.100[.]68
"A significant portion of the infrastructure shares common DNS records, IP addresses, and other registration data, indicating that these websites are part of a single coordinated campaign," said **Elena Shamshina**, technical lead of **F6**'s Threat Intelligence Department.
### A Precedent from 2017
**F6** noted a similar fraudulent scheme in 2017, where a Russian chemical company received calls from farmers regarding delayed deliveries of prepaid fertilizer orders. The farmers presented contracts with signatures believed to be company representatives, despite no such agreements existing.
Further investigation revealed a brandjacking effort where scammers had created a fraudulent website, "www.agrocenter-eurohem[.]ru," which was an almost perfect replica of the legitimate site. The only alterations were the bank account details and contact information.
"The attackers had also produced highly convincing commercial proposals on the company's official letterhead," **F6** detailed. "Although the documents appeared authentic, the payment details had been replaced with accounts controlled by the fraudsters. As a result, unsuspecting customers transferred money for goods that did not exist."
### International Reach and Advanced Deception
The current campaign is international in scope. While earlier iterations heavily relied on local .ru domains, newly established domains extensively use .com, .org, and .net top-level domains (**TLDs**). These websites are available in Russian, English, Arabic, and French.
**F6** also discovered a collection of fraudulent business documents, including fake commercial offers, contracts, and invoices, containing fabricated corporate email addresses and banking details.
"Analysis of these files indicates that the attackers prepare a complete set of business documentation designed to support the fake transaction and increase the victim's confidence," said **Vera Kolenikova**, senior specialist of **F6**'s Cybercrime Investigation Department. "As a result, victims lose money, while the legitimate companies whose brands are abused suffer reputational damage."
Perhaps the most concerning aspect of the campaign is the level of replication. After several victim companies published fraud warnings on their official websites, the unknown threat actors promptly copied those notices onto their fake counterparts, replacing references to the legitimate domains with their controlled fraudulent ones.
### Mitigation Strategies for Businesses
To protect against such threats, organizations are strongly advised to:
* **Exercise due diligence** on business partners using trusted sources and government business registries.
* **Independently verify** the legitimacy of subsidiaries and all contact information.
* **Scrutinize the supplier's website domain** and its registration date for any inconsistencies.
* **Always confirm payment details** through independent channels before transferring any funds.
For businesses engaged in international import and export operations, independent verification of contact and payment information is paramount.