Nine Years, Nearly 100 Fake Websites: Inside a Long-Running Scheme to Clone Russian Companies
- Fraud scale: Almost 100 fake domains were impersonating major Russian companies across the chemical, metallurgical, petrochemical, food, and financial sectors.
- Nine-year operation: The campaign ran for more than nine years, with the earliest identified domain registered in 2017.
- Real losses: A company from Azerbaijan reported losing approximately $150,000 in April 2025 to one fraudulent transaction.
A large-scale B2B fraud campaign spent more than nine years building clone websites of major Russian industrial firms to steal advance payments from international buyers. The fake sites, masquerading as official sites of major Russian industrial companies such as fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks, targeted customers with offers for goods that never existed.
The campaign primarily targeted organizations across the CIS, the Middle East, and Central Asia, including Kazakhstan, Uzbekistan, Azerbaijan, Türkiye, Pakistan, the UAE, Tajikistan, Turkmenistan, and Afghanistan. One victim, a company from Azerbaijan, reported losing approximately $150,000 in April 2025 to a single fraudulent transaction.
Clone Website Fraud Infrastructure
Most content was copied directly from legitimate company websites, with some fraudulent sites using lookalike domain names, and was available in English, French, Arabic, and Russian, according to a report shared with TechNadu by F6 Threat Intelligence and Cybercrime Investigation Departments.
Vera Kolenikova, Senior Specialist of F6's Cybercrime Investigation Department, said attackers prepared a complete set of business documentation to support fake transactions and increase victim confidence, including:
- commercial offers on official-looking letterheads,
- contracts,
- invoices with fake corporate email addresses.
How the B2B Scheme Operated
The threat actors specifically targeted the B2B sector and international trade, using cold calls, phishing emails, and lookalike corporate websites to communicate with potential customers and distribute business documents containing the banking details of fake "subsidiary" companies.
They contacted potential clients and directed them to exact copies of official sites, with only the contact details altered. In some cases, attackers hired unsuspecting sales representatives to make the initial cold calls, and at the final stage of contract negotiation, those representatives would hand the customer over to a "senior manager.”
"During the investigation, F6 specialists identified almost 100 fraudulent domains impersonating companies operating in the chemical, metallurgical, petrochemical, food, and financial industries," said Elena Shamshina, Technical Lead of F6's Threat Intelligence Department.
"The analysis showed that a significant portion of the infrastructure shares common DNS records, IP addresses, and other registration data, indicating that these websites are part of a single coordinated campaign."
Domain Migration and Altered Fraud Warnings
Where earlier campaigns relied on local .ru domains, the new operation makes extensive use of .com, .org, and .net top-level domains. F6 found that after several victim companies published fraud warnings on their own official websites, the attackers copied those very warnings onto their fake sites, simply swapping out references to the legitimate domain for their fraudulent one.
Kolenikova advised businesses to:
- Independently verify contact information and payment details before transferring funds.
- Verify the supplier's website domain and registration date.
- Be wary of artificial urgency.
Last week, the FBI updated a warning about scammers impersonating IC3 using fake profiles and AI-generated videos. In May, researchers observed fake LinkedIn collaboration emails abusing Adobe to track victims in a phishing campaign.




