AntiMalwareJuly 12, 2026🇷🇺Translated from Russian

GC Solar and SEG-T Launch Development of AI-Powered Security Email Gateway SEG-T to Counter Advanced Phishing Campaigns

GC Solar and SEG-T have announced the launch of a new Security Email Gateway solution aimed at strengthening corporate email protection through advanced multi-agent AI filtering. The initiative is led by co-founder of Secure-T, Khariton Nikishkin, with support from GC Solar, and directly addresses the rapid growth of sophisticated phishing campaigns that increasingly rely on pre-built toolkits and artificial intelligence.

Modern phishing operations now combine ready-made components such as management panels, distribution infrastructure, anti-bot mechanisms, and one-time code interception modules. Attackers further enhance these campaigns by using AI to generate more convincing messages and scale their reach. SEG-T is being developed to go beyond conventional technical analysis by evaluating the semantic content of emails, including tone, signs of psychological manipulation, attempts to establish trust, create fear, or pressure recipients into immediate action.

The gateway will automatically block messages containing potentially dangerous elements such as links, archives, PDF files, executable files, SVG images, and other attachments that could carry malicious content. Developers have decided against including a built-in sandbox, arguing that the majority of current attacks rely on social engineering rather than malware code. However, the solution will allow integration with external sandboxes for high-risk attachments when needed.

SEG-T is designed to work seamlessly with other GC Solar products, including Solar webProxy for traffic inspection and Solar Dozor for monitoring the transmission of sensitive personal data such as INN, SNILS, passport details, and bank card numbers.

The platform will be available in multiple deployment models: cloud, on-premises networks, and Kubernetes environments. According to the developers, initial setup and commissioning of SEG-T should take approximately 15 minutes. GC Solar owns 49% of the project and previously increased its stake in Secure-T to a controlling interest. The new product continues the company’s strategic focus on defending against phishing, spam, malicious mailings, and targeted attacks on corporate email systems.

Related articles

BoletimSecFraud & Social Engineering

Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities

A criminal platform called Work Panel is turning fake technical support calls into structured operations aimed at taking over corporate accounts. The service combines target research, page cloning, telephony, and credential capture within a single control panel. It is linked to the group tracked as O-UNC-045, also known as Cordial Spider. Campaigns target users of multiple identity providers and combine telephone social engineering with fake authentication pages. Operators research names, job titles, corporate emails, phone numbers, and professional profiles before calling to impersonate help-desk staff. While one operator keeps the victim on the line, a manager monitors the phishing session in real time. Captured credentials are sent only to operation managers via Telegram, reducing internal theft risks among the criminals themselves.

AntiMalwareFraud & Social Engineering

Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers

Russian threat intelligence firm F6 has uncovered a phishing campaign that used counterfeit Ministry of Defense portals to target relatives of participants in the special military operation. The attackers registered lookalike domains and populated them with official logos, coats of arms, and navigation menus copied from the legitimate mil.ru site, leaving only the registration form under their control. Victims were invited to register for state awards ceremonies and asked to supply full name, phone number, passport details, SNILS, and INN; an additional “Add guest” button collected the same information for accompanying persons. The stolen data can be used to reset access to government services, apply for microloans, or launch follow-on social-engineering attacks against military families. F6 analysts noted that the fraudulent pages were likely generated with a large language model, evidenced by an unhandled JSON error that appeared only after data submission. Although the discovered domains have been blocked inside Russia, the low technical barrier means new clones can be stood up quickly.

AntiMalwareFraud & Social Engineering

Russia to Launch Unified Payment Card Registry in 2026 to Combat Dropper Fraud Schemes

Starting September 1, 2026, Russia will introduce a single nationwide system for recording all payment cards issued by domestic banks. The registry will include every card regardless of the payment system used, covering existing Visa and Mastercard products as well as expired cards that banks continue to service. The measure is designed to give banks visibility into the total number of cards held by any individual across multiple institutions, thereby disrupting dropper schemes that rely on multiple accounts for laundering stolen funds. No immediate mass closure of cards will occur; instead, the first year will focus on data collection and preparation. From September 1, 2027, a hard limit of 20 cards per person will apply to new issuances only, while existing cards above the limit will remain operational. The policy grants individuals time to decide which cards they truly need before the issuance restriction takes effect.

AntiMalwareFraud & Social Engineering

Scammers Launch Fake Cyberpolice Russia Telegram Bot to Steal Accounts and Sell Fake Subscriptions

Fraudsters have created a counterfeit Telegram bot impersonating Russia's Cyberpolice, complete with official insignia and a convincing backstory. The bot promotes a paid subscription service for protection against cyber threats, essentially selling users defense against the scammers themselves. In a second attack vector, the bot requests a six-digit confirmation code, which grants attackers full access to the victim's Telegram account. Cyberpolice Russia has publicly stated that its units do not provide any paid services for threat notifications or protection. The legitimate bot operates under the exact handle cyberpolicerus_bot, and users are advised to verify the name character by character because scammers frequently alter letters or add symbols. Victims are reminded never to share six-digit Telegram codes with anyone, including entities claiming to represent law enforcement.