AntiMalwareJuly 13, 2026🇷🇺Translated from Russian

Looking for Gasoline? Hand Over Your Account: Scammers Launch Fake Gas Station Card Phishing Sites Targeting Fuel Shortages

Cybercriminals are exploiting ongoing fuel shortages and long queues at gas stations by deploying sophisticated phishing campaigns that trick users into surrendering access to their messenger accounts. Security researchers at F6 have discovered more than 60 fraudulent websites designed to look like official gas station locator services, game platforms, marketplaces, and video hosting sites.

How the Scam Operates

The attackers promise victims practical help such as real-time maps showing where gasoline is available, electronic fuel coupons, or bonus rewards in popular games. To “activate” these offers, users are asked to enter their phone number and then confirm it by inputting a one-time code sent via SMS. This simple step hands the attackers control over the victim’s messenger account.

Once inside, the criminals can read private conversations, download photos, videos, and documents, browse contact lists, and send messages while impersonating the account owner. In many cases, the legitimate user retains partial access and may not immediately notice the intrusion, allowing the attackers to operate undetected for extended periods.

Convincing Fake Interfaces

The phishing pages are built to appear authentic. Visitors are invited to choose fuel type and region; the site then claims to have located several stations. Instead of displaying the list, however, a “phone confirmation” form appears. In another variant, the criminals clone the design of legitimate services and require messenger authorization to receive a nonexistent electronic coupon.

Targeting Children and Additional Disguises

The same network also targets younger users. Under the guise of the popular game Brawl Stars, children are offered free loot boxes and in-game currency after logging in through their messenger. More than half of the identified sites impersonate marketplace brands, while 19 percent pose as social platforms. The remaining pages mimic gas station maps, video services, games, and classified advertisement boards.

Domain Patterns and Response

Most of these malicious pages are hosted on the domain zones .site, .click, .shop, .lol, and .xyz. F6 has already submitted the discovered domains for blocking, yet new addresses continue to appear as the campaign evolves.

Related articles

AntiMalwareFraud & Social Engineering

Beeline Subscribers Targeted in Mass SIM Hijacking via Remote eSIM Issuance

Beeline customers have encountered widespread attempts to hijack mobile numbers through unauthorized remote issuance of eSIM cards. Attackers required only a single careless confirmation from the user to complete the takeover, bypassing traditional SMS or push notifications. The scheme presented a system-level prompt on the smartphone screen requesting login to the operator's personal account, after which a virtual SIM was issued and the physical card blocked. One victim was Kommersant FM editor-in-chief Vladislav Viktorov. Specialist Alexander Baulin suggested possible infrastructure compromise at the operator, though Beeline denied this and described the incident as a coordinated attack on remote SIM issuance mechanisms. The company stated it repelled the assault, with only isolated successful hijackings occurring, and is assisting affected users. Similar attacks have impacted the entire telecom market since the start of the year, enabling fraudsters to access banking apps, government services, and other accounts tied to the number.

AntiMalwareFraud & Social Engineering

Yandex Rolls Out Universal Anti-Fraud Platform to Block Bots and Manipulation Schemes

Yandex has begun deploying its Universal Anti-Fraud system, a single AI-driven platform designed to detect bots, ticket scalping, and other forms of digital fraud across multiple services. The new solution can be integrated into a service within two to four days, replacing the previous months-long process of building separate defenses for each product. Dozens of Yandex services, including Eda, Afisha, Puteshestviya, and applications powered by Alice, are already connected to the platform. In Afisha the system identifies bots that mass-book tickets for popular events to create artificial scarcity, while in Eda it flags repeated fraudulent complaints aimed at obtaining compensation. The platform combines neural networks, analytical methods, and more than one hundred attack-pattern rules, analyzing traffic in real time and applying service-specific parameters. A key advantage is centralized updating: once a new fraud scheme is identified, protections are distributed instantly to all connected products.

HabrFraud & Social Engineering

Protecting C-Suite Leaders: Defending Executives Against Targeted Cyberattacks

According to PT EdTechLab data, 12% of registered data leaks in Russia originate from attacks on top management. Executives often combine maximum privileges with lax cyber hygiene and public visibility, creating high-value targets. The article outlines three primary attack scenarios: targeted whaling phishing with deepfakes, compromise of personal devices used for both work and private tasks, and account takeover via weak passwords or SIM swapping. Detailed recommendations include mandatory multi-factor authentication, separate corporate devices or MDM solutions, EDR coverage, strict password policies, and network segmentation. The piece stresses that technical measures must be paired with direct communication using business impact language to secure executive buy-in and set an example for the wider organization.

Security NEXTFraud & Social Engineering

IPA Reports Record High Fake Warning Scam Consultations in Q2 2026

The Information Processing Promotion Agency (IPA) recorded 3,832 personal security consultations in the second quarter of 2026, marking an 8.5 percent increase from the previous quarter. Fake warning scams, which display fabricated malware alerts to frighten users into contacting fraudsters, rose sharply to 1,428 cases, a 23.7 percent jump and the highest figure in two years. These scams carry risks of financial loss and device compromise through fake support services. Consultations dipped temporarily after arrests in May 2025 but have now exceeded levels seen before those arrests. Phishing reports also increased slightly to 146 cases, including schemes impersonating the National Tax Agency. The trend of rising fake warning incidents has continued for three consecutive quarters, underscoring the need for ongoing public vigilance.