# The Long Con: How a Nine-Year Brandjacking Ring Stole Millions from Commodity Traders


There's patient, and then there's this. While most fraud operations measure their lifespan in months before law enforcement dismantles them or the infrastructure burns, a campaign quietly cloning the websites of Russian industrial companies has been running since 2017 — through geopolitical upheaval, sanctions regimes, a global pandemic, and the restructuring of Eurasian trade — and is still active today.


The operation, documented this week by Russian cybersecurity firm F6, is a masterclass in low-tech, high-return fraud aimed squarely at B2B buyers in commodity markets. No zero-days. No ransomware. Just convincing fakes, patient operators, and the exploitation of one of the oldest vulnerabilities in commerce: trust placed in a logo and a professional-looking invoice.


## Built for the Commodity Trade


The choice of targets is deliberate and revealing. Fertilizer manufacturers, petrochemical producers, metallurgical plants, logistics operators, banks — these aren't sexy tech companies with sophisticated security teams running bug bounties. They're industrial firms operating in bulk commodity markets where procurement happens through formal tender processes, advance payments for large orders are standard practice, and buyers frequently deal with vendors they've never met in person.


That last detail is the unlock. A company in Azerbaijan buying 500 tonnes of potash from a Russian supplier doesn't fly someone to Moscow first. They exchange documents, negotiate via email, wire the prepayment, and wait for the shipment. The fraudsters didn't invent advance payment fraud — they industrialized it.


The mechanics are refined to a point that suggests years of operational learning. Attackers create near-perfect clones of legitimate company websites, copy all the real content, and change exactly two things: the banking details and the contact information. Then they wait, or they reach out. Cold calls come in multiple languages — English, French, Arabic, Russian — targeting international customers in CIS countries with a pitch that the real company would recognize as their own sales script.


The most chilling detail in F6's report: the operation has at times hired actual sales representatives who don't know they're working for a fraud ring. These unwitting employees make the initial cold contact, build rapport, close the negotiation — and then hand the client off to a "senior manager" for the final steps. At that point, the customer is talking directly to the criminals, who produce commercially convincing proposals on stolen letterhead, complete with contracts and invoices routing payment to accounts they control.


One Azerbaijani firm lost $150,000 this way in April 2025. That's a single documented victim. The operation runs nearly 100 counterfeit domains.


## The Infrastructure Tells a Story


F6's technical team linked a significant chunk of the fake domain infrastructure to two IP addresses: 212.127.73[.]235 and 167.86.100[.]68. Shared DNS records, registration data, and hosting patterns across the domain set confirm this isn't a loose collection of independent scammers — it's a coordinated campaign run by a single actor or tightly coordinated group.


The earliest connected domain traces to 2017, when a Russian chemical company started fielding calls from confused farmers asking why their prepaid fertilizer orders hadn't arrived. The farmers had contracts. They had signatures. They had receipts. None of it was real. The scammers had built a clone of the company's site — www.agrocenter-eurohem[.]ru — that was visually indistinguishable from the legitimate one except for the payment details buried in documents most buyers don't scrutinize character-by-character.


Nine years of operational continuity on the same infrastructure cluster is unusual. It suggests either that the operators feel minimal heat from law enforcement, or that the targets — primarily mid-size B2B buyers in emerging markets — have limited appetite or capacity to pursue cross-border fraud cases. Probably both.


## What Changes When Trade Routes Do


Context matters here, and most coverage of this disclosure won't provide it. The period from 2022 onward reshaped Eurasian commodity trade significantly. Russian firms operating under Western sanctions found their traditional Western customers cutting ties, while buyers in Central Asia, the Middle East, and North Africa stepped in to fill procurement gaps. New counterparties, unfamiliar vendors, unconventional payment channels — the exact conditions under which a polished fake website and a plausible cold call become significantly more effective.


The campaign's multilingual posture — English, French, Arabic, Russian — isn't accidental. It maps precisely onto the geography of commodity buyers who have increased trade exposure to Russian industrial suppliers in the past four years. Buyers in Algeria, Morocco, the Gulf states, and across the former Soviet Union have been building new supplier relationships in a compressed timeframe. Due diligence shortcuts follow.


## Indicators and What to Actually Do


F6 has published the two primary IP addresses associated with the infrastructure. Any procurement team or third-party risk function operating in commodity markets with CIS-region suppliers should be running those against their vendor communication logs immediately.


Beyond the specific IOCs, the structural defense is straightforward but rarely enforced:


  • Verify banking details through a separate channel before any wire. Call the supplier's publicly listed number — not the number on the invoice. Every time. Without exception.
  • Check domain registration dates. A "major Russian fertilizer producer" with a website registered six months ago is not a major Russian fertilizer producer.
  • Train procurement staff on document-level fraud. Forged letterhead is not hard to produce. Payment details are the one thing that should never be accepted from a document alone.
  • Flag cold outreach that escalates unusually fast to a "senior manager." The handoff pattern F6 documented is a specific tell.

  • ## HackWire Analysis


    Nine years is a long time to run a fraud operation targeting the same methods, the same geography, and the same industry verticals — and that longevity deserves more scrutiny than it's getting.


    The conventional framing treats this as an advance payment scam that happens to involve fake websites. But the real story is about the economics of B2B fraud in commodity markets. The ticket sizes are large enough to justify significant operational investment, the victims lack the forensic capacity to attribute the loss, cross-border jurisdiction makes prosecution difficult, and the underlying vulnerabilities — advance payment norms, limited supplier verification, heavy document reliance — are structural features of how these markets work. They're not going away.


    What's also missing from most coverage: the campaign's 2022-2026 expansion almost certainly tracks the disruption in established trade relationships caused by sanctions. New buyers entering unfamiliar markets are exactly the population most susceptible to a polished impersonation of a supplier they've been told is legitimate. The fraudsters didn't create the vulnerability — geopolitics did. They're just exploiting it systematically.


    There's also an uncomfortable parallel to business email compromise (BEC), which has cost global businesses over $50 billion since 2013 according to FBI IC3 data. This campaign is essentially BEC with a full infrastructure layer — fake sites instead of spoofed sender domains. The defense is the same: out-of-band verification of payment details is the only reliable control. No amount of email filtering or endpoint security stops a wire transfer initiated because someone trusted a convincing PDF.


    Defenders in procurement-heavy industries — agriculture inputs, metals, chemicals, logistics — should treat this disclosure as an operational prompt, not just threat intelligence. Pull your recent wire transfers against unknown or recently onboarded CIS-region vendors. Check the domains those vendors presented against the F6 IP indicators. And seriously evaluate whether your payment authorization process requires any verification of banking details beyond the invoice itself.


    — HackWire Editorial


    ---


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)