AntiMalwareJuly 13, 2026🇷🇺Translated from Russian

Looking for Gasoline? Hand Over Your Account: Scammers Launch Fake Gas Station Card Phishing Sites Targeting Fuel Shortages

Cybercriminals are exploiting ongoing fuel shortages and long queues at gas stations by deploying sophisticated phishing campaigns that trick users into surrendering access to their messenger accounts. Security researchers at F6 have discovered more than 60 fraudulent websites designed to look like official gas station locator services, game platforms, marketplaces, and video hosting sites.

How the Scam Operates

The attackers promise victims practical help such as real-time maps showing where gasoline is available, electronic fuel coupons, or bonus rewards in popular games. To “activate” these offers, users are asked to enter their phone number and then confirm it by inputting a one-time code sent via SMS. This simple step hands the attackers control over the victim’s messenger account.

Once inside, the criminals can read private conversations, download photos, videos, and documents, browse contact lists, and send messages while impersonating the account owner. In many cases, the legitimate user retains partial access and may not immediately notice the intrusion, allowing the attackers to operate undetected for extended periods.

Convincing Fake Interfaces

The phishing pages are built to appear authentic. Visitors are invited to choose fuel type and region; the site then claims to have located several stations. Instead of displaying the list, however, a “phone confirmation” form appears. In another variant, the criminals clone the design of legitimate services and require messenger authorization to receive a nonexistent electronic coupon.

Targeting Children and Additional Disguises

The same network also targets younger users. Under the guise of the popular game Brawl Stars, children are offered free loot boxes and in-game currency after logging in through their messenger. More than half of the identified sites impersonate marketplace brands, while 19 percent pose as social platforms. The remaining pages mimic gas station maps, video services, games, and classified advertisement boards.

Domain Patterns and Response

Most of these malicious pages are hosted on the domain zones .site, .click, .shop, .lol, and .xyz. F6 has already submitted the discovered domains for blocking, yet new addresses continue to appear as the campaign evolves.

Related articles

HabrFraud & Social Engineering

The Human Factor in Phishing: Why Employees Wait Nine Days to Report Credential Theft

A detailed case analysis reveals how an employee clicked a phishing link, entered credentials, and realized the mistake within a minute, yet security teams only discovered the incident nine days later through an automated rule rather than a human report. The delay stemmed from immediate shame and motivated reasoning that allowed the victim to convince themselves no further action was needed, including the false belief that changing the password resolved the issue. This nine-day window left attacker sessions active, permitted potential mailbox forwarding rules to exfiltrate data, and risked rotating logs that erased forensic evidence. The article examines how corporate cultures that frame incidents as blameworthy events actively discourage reporting and turn minor phishing successes into prolonged investigations involving third parties. Recommendations include creating a no-blame reporting policy with clear boundaries, implementing one-click in-client reporting buttons, and shifting metrics from click rates to reporting speed and volume. The analysis stresses that even strong technical detection cannot fully replace rapid human signals when cultural barriers remain unaddressed.

AntiMalwareFraud & Social Engineering

Fake GTA and Ghost Casino Apps Flood Google Play Early Access with Scam Promises

Unscrupulous developers are exploiting Google Play's Early Access program to distribute applications that make false promises of earnings through fake games and casino experiences. These apps lack public ratings and reviews, preventing disappointed users from warning others before installation. Bitdefender reports that the scheme is heavily promoted via advertisements on TikTok, Facebook, and other social networks, often featuring deepfakes of actors, athletes, and celebrities to build credibility. Users are lured with offers of PayPal payments, cryptocurrency, gift cards, and casino jackpots, but the apps deliberately slow progress near withdrawal thresholds. After installation, the software displays generous virtual winnings that never translate into real payouts. The campaign relies on aggressive advertising and misleading interfaces to maximize installations before users realize the fraud.

AntiMalwareFraud & Social Engineering

BI.ZONE Mail Security 3.0 Enhances Detection of Password-Protected Archives and Spam Variants

BI.ZONE has released Mail Security 3.0, introducing new mechanisms to detect email threats and improved tools for administrators. The updated system now assigns additional risk scores to password-protected archives when their contents cannot be unpacked, without automatically classifying the archive itself as malicious. It also compares message texts to identify near-identical emails used in spam campaigns where attackers slightly alter wording to evade filters. Administrators can now incorporate SPF and DKIM verification results into delivery rules to better distinguish legitimate senders from impersonators. According to BI.ZONE statistics, phishing accounted for 90 percent of illegitimate email traffic in the first half of 2026. Additional protections include CAPTCHA challenges after repeated failed login attempts on administrative accounts. The release also adds bulk management of rules, improved logging with a side panel for message details, a new Events section, and Syslog export to external SIEM systems.

AntiMalwareFraud & Social Engineering

F6 and MAX Neutralize Over 2,550 External Phishing and Scam Resources in Two-Month Operation

F6 and the MAX messenger have jointly blocked more than 2,550 malicious external websites used for phishing, scams, and other forms of online fraud. The effort relied on the F6 Digital Risk Protection platform, which continuously scans for fake authentication pages and fraudulent resources targeting users. Monitoring took place during July and August 2026, after which experts from both organizations arranged for the sites to be taken down. The action focused exclusively on external resources and did not involve any malicious content hosted inside the MAX messenger itself. F6 Digital Risk Protection head Stanislav Goncharov noted that regular takedowns can reduce attacker activity over time, yet users must still verify website addresses manually before entering credentials or payment data.