A network of domains hosting login pages for likely fraudulent ship classification societies has been linked to entities operating under the names Hellas Naval Bureau of Shipping (HNBS), Med Lloyd Classification Society, International Marine Services (IMS), and Olymbos Naval. The organizations present themselves as recognized bodies authorized to certify vessel safety and compliance, and some are listed as recognized organizations by maritime administrations including Cameroon, Kenya, Comoros, Tanzania, Benin, and Gambia. Shared infrastructure, overlapping subdomains, similar website designs, and common hosting indicators suggest the entities are operationally connected.
The network has been tied to vessels associated with Iranian and Russian shadow fleets, raising concerns that fraudulent certification services are being used to support maritime sanctions evasion. One cited case involved the vessel SERANO II, which Chinese maritime authorities said carried a non-compliant inspection certificate with an incorrect QR code; the Zhoushan Maritime Safety Administration said Med Lloyd Classification Society bore significant responsibility for arbitrarily issuing statutory inspection certificates that contributed to the vessel’s detention. The findings indicate cyber-enabled maritime deception is being used to help high-risk vessels obtain paperwork needed to continue operating.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
A cited April 2025 article by the Zhoushan Maritime Safety Administration said the vessel SERANO II carried a non-compliant inspection certificate with an incorrect QR code. The article stated that Med Lloyd Classification Society bore significant responsibility for arbitrarily issuing statutory inspection certificates that contributed to the vessel’s detention.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.