AntiMalwareAugust 4, 2026🇷🇺Translated from Russian

Positive Technologies Uncovers Disinformation Factory Linking 45 Domains and 74 Telegram Channels

Researchers from Positive Technologies have identified a large-scale disinformation factory that combined fraudulent emails, fabricated news sites, and coordinated social-media amplification. The operation involved 45 domains and at least 74 Telegram channels, forming a single, self-sustaining information network.

The scheme started with emails sent on behalf of Russian government agencies and major companies. Attackers used domains such as minpromtorg.digital, gosuslugi.digital, and rosstat.live that closely resembled official addresses but employed zones including .digital, .live, and .work. Recipients were asked to provide lists of employees, salary information, and other internal data, likely to support subsequent targeted phishing campaigns. The messages contained no malicious attachments; their purpose was to verify active addresses and willing respondents.

At the same time, operators ran a parallel network of pseudo-news websites. These platforms blended authentic publications with invented stories, referenced nonexistent sources, and adopted regional narratives. Among the identified domains were rulenta.live, crime24.live, daganews.ru, and pressklub.az. Fabricated claims published on one site were frequently cited by others as authoritative confirmation, creating a closed loop of apparent legitimacy.

Distribution relied on multiple platforms: VKontakte, Odnoklassniki, YouTube, Instagram, TikTok, and Telegram. Channels were disguised as regional or patriotic communities and often posted identical material simultaneously, driving traffic to the linked websites. Some channels had accumulated thousands of subscribers.

Investigators observed a possible connection to the cybercriminal group Rare Werewolf. One domain previously hosted an archive named bk.rar, a path previously associated with the group’s infrastructure. However, Positive Technologies stated that available evidence is insufficient for definitive attribution and described the link as probable rather than confirmed.

The operation illustrates a complete information pipeline: reconnaissance emails collect contact data, pseudo-news sites lend credibility to fabrications, and synchronized social-media activity ensures wide dissemination to targeted audiences.

Related articles

AntiMalwareFraud & Social Engineering

Russian Interior Ministry Advises Citizens Against Posting Personal Dossiers on Social Media

The Russian Ministry of Internal Affairs has issued a public warning urging citizens to reduce the amount of personal information shared on social networks. Details such as places of study and work, home addresses, and family information should remain outside public profiles to avoid attracting the attention of fraudsters and recruiters. According to materials cited by RIA Novosti, such digital self-portraits allow malicious actors to study potential victims, identify vulnerabilities, and craft personalized communication scenarios. The ministry also recommends avoiding public discussions of personal views and refraining from answering questions from strangers. Users are advised to verify profile ownership before engaging and to block suspicious accounts while reporting them to platform moderators. This marks the second such advisory from the ministry within recent months, following an October 2025 reminder about the risks of exposing full names, birth dates, and other identifiable data.

BoletimSecFraud & Social Engineering

Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities

A criminal platform called Work Panel is turning fake technical support calls into structured operations aimed at taking over corporate accounts. The service combines target research, page cloning, telephony, and credential capture within a single control panel. It is linked to the group tracked as O-UNC-045, also known as Cordial Spider. Campaigns target users of multiple identity providers and combine telephone social engineering with fake authentication pages. Operators research names, job titles, corporate emails, phone numbers, and professional profiles before calling to impersonate help-desk staff. While one operator keeps the victim on the line, a manager monitors the phishing session in real time. Captured credentials are sent only to operation managers via Telegram, reducing internal theft risks among the criminals themselves.

AntiMalwareFraud & Social Engineering

Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers

Russian threat intelligence firm F6 has uncovered a phishing campaign that used counterfeit Ministry of Defense portals to target relatives of participants in the special military operation. The attackers registered lookalike domains and populated them with official logos, coats of arms, and navigation menus copied from the legitimate mil.ru site, leaving only the registration form under their control. Victims were invited to register for state awards ceremonies and asked to supply full name, phone number, passport details, SNILS, and INN; an additional “Add guest” button collected the same information for accompanying persons. The stolen data can be used to reset access to government services, apply for microloans, or launch follow-on social-engineering attacks against military families. F6 analysts noted that the fraudulent pages were likely generated with a large language model, evidenced by an unhandled JSON error that appeared only after data submission. Although the discovered domains have been blocked inside Russia, the low technical barrier means new clones can be stood up quickly.

AntiMalwareFraud & Social Engineering

Russia to Launch Unified Payment Card Registry in 2026 to Combat Dropper Fraud Schemes

Starting September 1, 2026, Russia will introduce a single nationwide system for recording all payment cards issued by domestic banks. The registry will include every card regardless of the payment system used, covering existing Visa and Mastercard products as well as expired cards that banks continue to service. The measure is designed to give banks visibility into the total number of cards held by any individual across multiple institutions, thereby disrupting dropper schemes that rely on multiple accounts for laundering stolen funds. No immediate mass closure of cards will occur; instead, the first year will focus on data collection and preparation. From September 1, 2027, a hard limit of 20 cards per person will apply to new issuances only, while existing cards above the limit will remain operational. The policy grants individuals time to decide which cards they truly need before the issuance restriction takes effect.