AntiMalwareJuly 31, 2026🇷🇺Translated from Russian

Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers

Russian cybersecurity company F6 has disclosed a targeted phishing operation that impersonated the Ministry of Defense to collect personal data from relatives of participants in the special military operation.

Attackers created several counterfeit websites that closely mimicked the official resource of the ministry. One of the domains, mil-ru-gov[.]info, was deliberately chosen to resemble the legitimate mil.ru address. The pages featured the ministry’s logo, coat of arms, and navigation menu, with almost all links pointing to genuine ministry content. This visual authenticity was intended to lower visitors’ suspicions, leaving only the registration form under attacker control.

Relatives were told they could register for an awards ceremony honoring fallen service members. The form requested full name, telephone number, passport data, SNILS, and INN. An additional “Add guest” function allowed the same information to be collected for accompanying persons, expanding the dataset in a single session.

Once obtained, the information can be used to reset access to state digital services, open microloans, or conduct further social-engineering attacks. Knowledge of a relative’s name and phone number enables attackers to craft convincing stories about compromised accounts or to pivot toward banking applications.

Researchers at F6 believe the sites were assembled with the assistance of a large language model. A visible JSON parsing error in the registration form indicated that the code was produced rapidly and never fully sanitized. The error did not prevent data exfiltration; it appeared only after the information had already been sent to the attackers’ server.

Distribution methods remain under investigation, but the links were likely sent directly via messengers and email. The identified domains have been blocked in Russia; however, nothing prevents the operators from registering new ones.

Related articles

AntiMalwareFraud & Social Engineering

Positive Technologies Uncovers Disinformation Factory Linking 45 Domains and 74 Telegram Channels

Researchers at Positive Technologies have exposed an integrated disinformation operation that combined fake government emails with a network of pseudo-news websites and synchronized social media channels. The campaign began with emails sent from lookalike domains such as minpromtorg.digital and gosuslugi.digital, requesting employee lists and salary data to prepare targeted phishing attacks. Parallel to the email activity, operators maintained at least 45 domains including rulenta.live and crime24.live that mixed genuine stories with fabricated content and cited nonexistent sources. These sites were amplified through dozens of Telegram channels and accounts on VKontakte, Odnoklassniki, YouTube, Instagram, and TikTok, creating a self-reinforcing loop where fabricated claims were quoted back as credible reporting. Investigators noted a possible infrastructure overlap with the cybercriminal group Rare Werewolf, although direct attribution remains unconfirmed. The operation demonstrates a complete information pipeline from initial reconnaissance via email to wide distribution of disinformation across multiple platforms.

AntiMalwareFraud & Social Engineering

Russian Interior Ministry Advises Citizens Against Posting Personal Dossiers on Social Media

The Russian Ministry of Internal Affairs has issued a public warning urging citizens to reduce the amount of personal information shared on social networks. Details such as places of study and work, home addresses, and family information should remain outside public profiles to avoid attracting the attention of fraudsters and recruiters. According to materials cited by RIA Novosti, such digital self-portraits allow malicious actors to study potential victims, identify vulnerabilities, and craft personalized communication scenarios. The ministry also recommends avoiding public discussions of personal views and refraining from answering questions from strangers. Users are advised to verify profile ownership before engaging and to block suspicious accounts while reporting them to platform moderators. This marks the second such advisory from the ministry within recent months, following an October 2025 reminder about the risks of exposing full names, birth dates, and other identifiable data.

BoletimSecFraud & Social Engineering

Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities

A criminal platform called Work Panel is turning fake technical support calls into structured operations aimed at taking over corporate accounts. The service combines target research, page cloning, telephony, and credential capture within a single control panel. It is linked to the group tracked as O-UNC-045, also known as Cordial Spider. Campaigns target users of multiple identity providers and combine telephone social engineering with fake authentication pages. Operators research names, job titles, corporate emails, phone numbers, and professional profiles before calling to impersonate help-desk staff. While one operator keeps the victim on the line, a manager monitors the phishing session in real time. Captured credentials are sent only to operation managers via Telegram, reducing internal theft risks among the criminals themselves.

AntiMalwareFraud & Social Engineering

Russia to Launch Unified Payment Card Registry in 2026 to Combat Dropper Fraud Schemes

Starting September 1, 2026, Russia will introduce a single nationwide system for recording all payment cards issued by domestic banks. The registry will include every card regardless of the payment system used, covering existing Visa and Mastercard products as well as expired cards that banks continue to service. The measure is designed to give banks visibility into the total number of cards held by any individual across multiple institutions, thereby disrupting dropper schemes that rely on multiple accounts for laundering stolen funds. No immediate mass closure of cards will occur; instead, the first year will focus on data collection and preparation. From September 1, 2027, a hard limit of 20 cards per person will apply to new issuances only, while existing cards above the limit will remain operational. The policy grants individuals time to decide which cards they truly need before the issuance restriction takes effect.