Researchers disclosed a long-running fraud operation that has impersonated major Russian companies since at least 2017, using cloned corporate websites, phishing emails, and cold calls to trick international businesses into paying in advance for nonexistent goods and services. The campaign has primarily targeted B2B trade customers in CIS countries, but the fake sites were also built to reach a wider audience with Russian, English, French, and Arabic content. Attackers posed as firms in sectors including manufacturing, logistics, and banking, then sent forged contracts, invoices, and other business documents containing fraudulent banking details.
Investigators linked nearly 100 counterfeit domains to the scheme through shared DNS records, registration patterns, and infrastructure including IP addresses 212.127.73[.]235 and 167.86.100[.]68. The fraudulent sites copied legitimate company branding and content, and in some cases even reproduced anti-fraud warnings from the real firms to appear credible. Researchers said newer domains increasingly used .com, .org, and .net rather than .ru, while stolen funds were routed to shell-company bank accounts. In one documented case, an Azerbaijani company reportedly lost $150,000 in April 2025 after sending payment to the scammers.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
In April 2025, an Azerbaijani company reportedly sent a $150,000 advance payment to the fraudsters after being deceived by the impersonation scheme.
Researchers said the impersonation and advance-payment fraud operation has been active since 2017, using cloned websites, phishing emails, and cold calls to target international businesses, especially in CIS countries.
Researchers disclosed that they had connected nearly 100 fake domains to the campaign through shared infrastructure such as DNS records, registration data, and IP addresses, revealing the scale of the operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.