Positive Technologies Uncovers Disinformation Factory Linking 45 Domains and 74 Telegram Channels
Researchers from Positive Technologies have identified a large-scale disinformation factory that combined fraudulent emails, fabricated news sites, and coordinated social-media amplification. The operation involved 45 domains and at least 74 Telegram channels, forming a single, self-sustaining information network.
The scheme started with emails sent on behalf of Russian government agencies and major companies. Attackers used domains such as minpromtorg.digital, gosuslugi.digital, and rosstat.live that closely resembled official addresses but employed zones including .digital, .live, and .work. Recipients were asked to provide lists of employees, salary information, and other internal data, likely to support subsequent targeted phishing campaigns. The messages contained no malicious attachments; their purpose was to verify active addresses and willing respondents.
At the same time, operators ran a parallel network of pseudo-news websites. These platforms blended authentic publications with invented stories, referenced nonexistent sources, and adopted regional narratives. Among the identified domains were rulenta.live, crime24.live, daganews.ru, and pressklub.az. Fabricated claims published on one site were frequently cited by others as authoritative confirmation, creating a closed loop of apparent legitimacy.
Distribution relied on multiple platforms: VKontakte, Odnoklassniki, YouTube, Instagram, TikTok, and Telegram. Channels were disguised as regional or patriotic communities and often posted identical material simultaneously, driving traffic to the linked websites. Some channels had accumulated thousands of subscribers.
Investigators observed a possible connection to the cybercriminal group Rare Werewolf. One domain previously hosted an archive named bk.rar, a path previously associated with the group’s infrastructure. However, Positive Technologies stated that available evidence is insufficient for definitive attribution and described the link as probable rather than confirmed.
The operation illustrates a complete information pipeline: reconnaissance emails collect contact data, pseudo-news sites lend credibility to fabrications, and synchronized social-media activity ensures wide dissemination to targeted audiences.
Related articles
Behavioral Anti-Fraud: How Systems Analyze User Actions Beyond Device and Browser Fingerprints
Anti-fraud systems are shifting from static device and browser fingerprinting toward continuous behavioral analysis powered by machine learning. The article explains why matching User-Agent strings with Canvas or font rendering is no longer sufficient, as bot developers can easily synchronize these static signals. Modern defenses now record dozens of micro-events during a session, including keystroke timing, mouse trajectories, scroll speed, and focus changes, to build a dynamic Trust Score. These models are trained on large clusters of real-user behavior and flag sessions whose patterns fall outside legitimate clusters even when fingerprints appear realistic. The text details dwell time, flight time, error-correction patterns, natural hand tremor, and acceleration curves governed by Fitts’s law as key biometric markers. It also covers browser-level signals such as Event.isTrusted, CDP artifacts, and navigator.webdriver flags that reveal automation frameworks. The discussion extends to mobile sensors and concludes that perfectly error-free, mathematically smooth input is itself a strong indicator of synthetic activity.
Free Online Panel Examines Rising Omnichannel Scams and Multichannel Fraud Tactics
The Brazilian human risk management firm Eskive is hosting its third free online panel on August 18 at 11 a.m. to address the growing threat of omnichannel cyber fraud. Experts will discuss how attackers combine multiple channels such as email, SMS, and other vectors to create more convincing social-engineering narratives that bypass traditional single-channel defenses. The event will feature CEO Priscila Meyer as moderator along with cyber threat intelligence specialist Thiago Bordini and Santa Catarina Civil Police investigator Elias Edenis. Participants will gain practical insights from real client simulations, live Q&A sessions, and interactive quizzes designed to improve organizational preparedness. The panel aims to highlight why users accustomed to recognizing basic phishing or smishing attempts remain vulnerable when fraudsters deploy coordinated, multi-channel campaigns.
OpenAI Disables Coordinated ChatGPT Network Used for Financial Scams and Identity Forgery
OpenAI has deactivated a coordinated network of ChatGPT accounts that supported financial fraud, romance scams, and identity forgery operations. Criminals leveraged the AI to generate fake personas, translate conversations, and craft targeted messages aimed at victims across multiple schemes. The investigation originated from reports of suspicious activity observed on WhatsApp. Scammers used the tool to produce forged documents including stock confirmations, legal notices, passports, and fake financial interfaces to increase credibility. Operations typically began on social media or messaging apps, building emotional trust or urgency before requesting deposits, activation fees, or nonexistent fines. Indicators of possible human trafficking and forced labor were also uncovered through job advertisements and internal discussions about worker control in Poipet. OpenAI has blocked the accounts and shared operational indicators with law enforcement and technology companies.
Russian Interior Ministry Advises Citizens Against Posting Personal Dossiers on Social Media
The Russian Ministry of Internal Affairs has issued a public warning urging citizens to reduce the amount of personal information shared on social networks. Details such as places of study and work, home addresses, and family information should remain outside public profiles to avoid attracting the attention of fraudsters and recruiters. According to materials cited by RIA Novosti, such digital self-portraits allow malicious actors to study potential victims, identify vulnerabilities, and craft personalized communication scenarios. The ministry also recommends avoiding public discussions of personal views and refraining from answering questions from strangers. Users are advised to verify profile ownership before engaging and to block suspicious accounts while reporting them to platform moderators. This marks the second such advisory from the ministry within recent months, following an October 2025 reminder about the risks of exposing full names, birth dates, and other identifiable data.