AntiMalwareJuly 31, 2026🇷🇺Translated from Russian

Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers

Russian cybersecurity company F6 has disclosed a targeted phishing operation that impersonated the Ministry of Defense to collect personal data from relatives of participants in the special military operation.

Attackers created several counterfeit websites that closely mimicked the official resource of the ministry. One of the domains, mil-ru-gov[.]info, was deliberately chosen to resemble the legitimate mil.ru address. The pages featured the ministry’s logo, coat of arms, and navigation menu, with almost all links pointing to genuine ministry content. This visual authenticity was intended to lower visitors’ suspicions, leaving only the registration form under attacker control.

Relatives were told they could register for an awards ceremony honoring fallen service members. The form requested full name, telephone number, passport data, SNILS, and INN. An additional “Add guest” function allowed the same information to be collected for accompanying persons, expanding the dataset in a single session.

Once obtained, the information can be used to reset access to state digital services, open microloans, or conduct further social-engineering attacks. Knowledge of a relative’s name and phone number enables attackers to craft convincing stories about compromised accounts or to pivot toward banking applications.

Researchers at F6 believe the sites were assembled with the assistance of a large language model. A visible JSON parsing error in the registration form indicated that the code was produced rapidly and never fully sanitized. The error did not prevent data exfiltration; it appeared only after the information had already been sent to the attackers’ server.

Distribution methods remain under investigation, but the links were likely sent directly via messengers and email. The identified domains have been blocked in Russia; however, nothing prevents the operators from registering new ones.

Related articles

HabrFraud & Social Engineering

Smart Engines Patents AI Method to Detect Holographic Security Features in Documents Using Visible Light Only

Smart Engines has developed and patented a new technique that identifies optically variable devices such as holograms on identity documents without requiring ultraviolet illumination. The approach relies on a standard document scanner equipped with six independently controlled LEDs that capture a sequence of six images under different lighting angles while the document and camera remain stationary. After dark-current correction and calibration against a white reference sheet, the system normalizes the images and computes per-pixel color-vector standard deviation to generate an OVD map. A simple thresholding and region-of-interest analysis then produces a binary verdict indicating whether a genuine holographic element is present. The method effectively distinguishes original documents from high-quality color prints, photocopies, and physical replicas that cannot reproduce the angle-dependent color shifts of real OVDs. All processing occurs with existing scanner hardware, demonstrating that algorithmic interpretation of controlled illumination can add a new authenticity signal without additional optics or spectral channels.

HabrFraud & Social Engineering

YooMoney's YuScan Automates E-commerce Risk Assessment Scanning Up to 1,000 Sites Per Hour

YooMoney has detailed the inner workings of its YuScan service, an automated auditing tool designed to help banks and payment providers identify websites that conceal prohibited or high-risk activities. Since 2020 the system has processed more than 550,000 merchant applications without resulting in any fines for servicing illegal operations. YuScan builds comprehensive site maps, executes JavaScript, and handles dynamic content using Playwright combined with Camoufox to evade modern anti-bot protections such as Cloudflare. The crawler is built on Scrapy with FastAPI and PostgreSQL, then applies ML models, embeddings, and LLMs to analyze text, images, reviews, and external signals including Roskomnadzor registries and WHOIS data. The automation has reduced manual review time dramatically, allowing half of compliant merchants to begin accepting payments within 24 hours. YooKassa now offers the service to other banks through NSPK, the operator of the Mir payment system.

AntiMalwareFraud & Social Engineering

Scammers Pose as Employers to Remotely Lock iPhones and Demand Ransom

Russian police have warned of a new social engineering scheme in which fraudsters impersonate potential employers to gain control of victims' Apple devices. The attackers instruct targets to sign out of their personal Apple accounts and authenticate using credentials supplied by the supposed employer. Once the device links to the fraudster's account, the scammers can remotely lock the iPhone or iPad and demand payment for unlocking it. Authorities emphasize that paying the ransom does not guarantee recovery of the device and may lead to further extortion demands. Victims are advised never to enter third-party Apple credentials on personal hardware and to contact Apple Support with proof of purchase if a device is already locked. The scheme exploits the Find My and Activation Lock features built into iOS devices.

AntiMalwareFraud & Social Engineering

Scammers Target Remote Workers with Fake Compensation for Home Internet and Devices

Russian remote employees are being targeted by fraudsters impersonating employers, government agencies, and corporate IT departments. Attackers lure victims with promises of compensation for home internet costs and personal computers, directing them to fake sites for identity verification or SMS code submission. Instead of receiving payments, victims risk handing over account credentials or banking details to criminals. Another tactic involves urgent messages from supposed IT services demanding immediate access renewal or software updates via malicious links. The pressure of urgency aims to bypass caution, leading users to click links, enter passwords, or execute files before verifying the sender. Home networks present additional risks because users manage their own routers and connected devices, unlike secured office environments. Experts from Yandex recommend changing default router passwords, updating firmware, disabling quick device pairing, and isolating smart devices on a separate guest network.