AntiMalwareJuly 31, 2026🇷🇺Translated from Russian

Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers

Russian cybersecurity company F6 has disclosed a targeted phishing operation that impersonated the Ministry of Defense to collect personal data from relatives of participants in the special military operation.

Attackers created several counterfeit websites that closely mimicked the official resource of the ministry. One of the domains, mil-ru-gov[.]info, was deliberately chosen to resemble the legitimate mil.ru address. The pages featured the ministry’s logo, coat of arms, and navigation menu, with almost all links pointing to genuine ministry content. This visual authenticity was intended to lower visitors’ suspicions, leaving only the registration form under attacker control.

Relatives were told they could register for an awards ceremony honoring fallen service members. The form requested full name, telephone number, passport data, SNILS, and INN. An additional “Add guest” function allowed the same information to be collected for accompanying persons, expanding the dataset in a single session.

Once obtained, the information can be used to reset access to state digital services, open microloans, or conduct further social-engineering attacks. Knowledge of a relative’s name and phone number enables attackers to craft convincing stories about compromised accounts or to pivot toward banking applications.

Researchers at F6 believe the sites were assembled with the assistance of a large language model. A visible JSON parsing error in the registration form indicated that the code was produced rapidly and never fully sanitized. The error did not prevent data exfiltration; it appeared only after the information had already been sent to the attackers’ server.

Distribution methods remain under investigation, but the links were likely sent directly via messengers and email. The identified domains have been blocked in Russia; however, nothing prevents the operators from registering new ones.

Related articles

BoletimSecFraud & Social Engineering

Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities

A criminal platform called Work Panel is turning fake technical support calls into structured operations aimed at taking over corporate accounts. The service combines target research, page cloning, telephony, and credential capture within a single control panel. It is linked to the group tracked as O-UNC-045, also known as Cordial Spider. Campaigns target users of multiple identity providers and combine telephone social engineering with fake authentication pages. Operators research names, job titles, corporate emails, phone numbers, and professional profiles before calling to impersonate help-desk staff. While one operator keeps the victim on the line, a manager monitors the phishing session in real time. Captured credentials are sent only to operation managers via Telegram, reducing internal theft risks among the criminals themselves.

AntiMalwareFraud & Social Engineering

Russia to Launch Unified Payment Card Registry in 2026 to Combat Dropper Fraud Schemes

Starting September 1, 2026, Russia will introduce a single nationwide system for recording all payment cards issued by domestic banks. The registry will include every card regardless of the payment system used, covering existing Visa and Mastercard products as well as expired cards that banks continue to service. The measure is designed to give banks visibility into the total number of cards held by any individual across multiple institutions, thereby disrupting dropper schemes that rely on multiple accounts for laundering stolen funds. No immediate mass closure of cards will occur; instead, the first year will focus on data collection and preparation. From September 1, 2027, a hard limit of 20 cards per person will apply to new issuances only, while existing cards above the limit will remain operational. The policy grants individuals time to decide which cards they truly need before the issuance restriction takes effect.

AntiMalwareFraud & Social Engineering

Scammers Launch Fake Cyberpolice Russia Telegram Bot to Steal Accounts and Sell Fake Subscriptions

Fraudsters have created a counterfeit Telegram bot impersonating Russia's Cyberpolice, complete with official insignia and a convincing backstory. The bot promotes a paid subscription service for protection against cyber threats, essentially selling users defense against the scammers themselves. In a second attack vector, the bot requests a six-digit confirmation code, which grants attackers full access to the victim's Telegram account. Cyberpolice Russia has publicly stated that its units do not provide any paid services for threat notifications or protection. The legitimate bot operates under the exact handle cyberpolicerus_bot, and users are advised to verify the name character by character because scammers frequently alter letters or add symbols. Victims are reminded never to share six-digit Telegram codes with anyone, including entities claiming to represent law enforcement.

AntiMalwareFraud & Social Engineering

Beeline Subscribers Targeted in Mass SIM Hijacking via Remote eSIM Issuance

Beeline customers have encountered widespread attempts to hijack mobile numbers through unauthorized remote issuance of eSIM cards. Attackers required only a single careless confirmation from the user to complete the takeover, bypassing traditional SMS or push notifications. The scheme presented a system-level prompt on the smartphone screen requesting login to the operator's personal account, after which a virtual SIM was issued and the physical card blocked. One victim was Kommersant FM editor-in-chief Vladislav Viktorov. Specialist Alexander Baulin suggested possible infrastructure compromise at the operator, though Beeline denied this and described the incident as a coordinated attack on remote SIM issuance mechanisms. The company stated it repelled the assault, with only isolated successful hijackings occurring, and is assisting affected users. Similar attacks have impacted the entire telecom market since the start of the year, enabling fraudsters to access banking apps, government services, and other accounts tied to the number.