Executive Summary
Since 2017, a sophisticated fraud campaign has been targeting international firms by creating counterfeit websites that closely mimic those of major Russian companies in sectors such as fertilizer manufacturing, petrochemicals, metallurgy, logistics, and banking. These fraudulent sites, available in multiple languages including English, French, Arabic, and Russian, are designed to deceive businesses into making advance payments for non-existent goods. The attackers employ tactics like cold calls, phishing emails, and fake corporate websites to initiate contact, eventually providing falsified business documents with fraudulent banking details. One notable incident in April 2025 involved an Azerbaijani company losing $150,000 through such a scheme. This prolonged campaign underscores the evolving nature of cyber fraud, highlighting the need for businesses to remain vigilant against increasingly sophisticated social engineering tactics. The use of multilingual fake websites and the recruitment of unwitting sales representatives indicate a high level of organization and adaptability among cybercriminals, posing significant risks to international trade and business operations.
Why This Matters Now
The persistence and sophistication of this nine-year fraud campaign highlight the urgent need for businesses to enhance their cybersecurity measures. As cybercriminals continue to refine their tactics, organizations must stay vigilant to protect against financial losses and reputational damage.
Attack Path Analysis
The attackers initiated the fraud campaign by creating lookalike websites of major Russian companies to deceive international firms into making advance payments for non-existent goods. They then escalated their scheme by impersonating legitimate company representatives, using fraudulent contact details to communicate with victims. Subsequently, they moved laterally by hiring unsuspecting sales representatives to make cold calls, furthering their reach to potential victims. The attackers established command and control by maintaining communication with victims through emails and phone calls, directing them to the fraudulent websites and providing fake banking details. They exfiltrated funds by deceiving victims into transferring advance payments to bank accounts controlled by the fraudsters. The impact of the campaign was significant financial loss to the victims, with one company losing $150,000 in a single transaction.
Kill Chain Progression
Initial Compromise
Description
Attackers created fraudulent websites mimicking legitimate Russian companies to deceive international firms.
MITRE ATT&CK® Techniques
Search Open Websites/Domains
Masquerading
Defacement: External Defacement
Browser Session Hijacking
Template Injection
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that all system components are protected from known vulnerabilities by installing applicable security patches.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Maintain a Cybersecurity Program
Control ID: 500.02
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Chemicals
Fertilizer manufacturers directly targeted in nine-year cloning campaign, exposing chemical companies to business email compromise and advance payment fraud schemes.
Oil/Energy/Solar/Greentech
Petrochemical companies specifically cloned in fraud operation, creating significant financial and reputational risks through fraudulent payment diversion and client deception.
International Trade/Development
Cross-border payment fraud targeting international firms creates substantial risk for trade organizations through compromised supplier verification and payment diversion attacks.
Import/Export
Russian company cloning directly impacts import/export sector through fraudulent advance payments, compromised supplier authentication, and disrupted international business relationships.
Sources
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Paymentshttps://thehackernews.com/2026/07/nine-year-fraud-campaign.htmlVerified
- Criminals are using AI website builders to clone major brandshttps://www.malwarebytes.com/blog/news/2026/02/criminals-are-using-ai-website-builders-to-clone-major-brandsVerified
- Website cloning: How to detect it, prevent it, and respondhttps://www.redpoints.com/blog/website-cloning/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely constrain the attackers' ability to exploit implicit trust within the network, thereby reducing their reach and potential impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attackers' ability to establish initial footholds through deceptive websites would likely be constrained, reducing the success rate of such impersonation attempts.
Control: Zero Trust Segmentation
Mitigation: The attackers' ability to escalate privileges through impersonation would likely be constrained, reducing the effectiveness of their fraudulent communications.
Control: East-West Traffic Security
Mitigation: The attackers' ability to move laterally within the network by leveraging unsuspecting individuals would likely be constrained, reducing their reach to potential victims.
Control: Multicloud Visibility & Control
Mitigation: The attackers' ability to maintain command and control over victims through deceptive communications would likely be constrained, reducing the effectiveness of their fraudulent directives.
Control: Egress Security & Policy Enforcement
Mitigation: The attackers' ability to exfiltrate funds through deceptive transactions would likely be constrained, reducing the success rate of financial fraud.
The overall financial impact on victims would likely be reduced, limiting the extent of monetary losses.
Impact at a Glance
Affected Business Functions
- Sales and Marketing
- Customer Service
- Financial Transactions
Estimated downtime: N/A
Estimated loss: $150,000
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access and limit the impact of compromised accounts.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Utilize Multicloud Visibility & Control to monitor and manage traffic across all cloud environments.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Deploy Inline IPS (Suricata) to detect and block known exploit patterns and malicious payloads.



