HabrAugust 26, 2026🇷🇺Translated from Russian

VC.ru Blocks Lawyer's Account After Article Exposing In-Platform Phishing Scheme

A lawyer writing under the name David Zamirovich on VC.ru since 2022 had his account blocked shortly after publishing material about a phishing campaign operating through articles on the platform itself.

The original trigger was a report on Habr describing how a victim lost 10k USDT after interacting with malicious links. Zamirovich summarized the attack pattern without naming individuals or posting unredacted screenshots.

The phishing mechanism relied on publishing normal-looking articles that passed moderation and gained search visibility. Attackers later replaced internal links with redirects through intermediaries that led to cloned services. Users connecting wallets and signing verification transactions lost funds.

Zamirovich's article focused on defensive advice and referenced the existing Habr analysis. One hour after publication the account received an automated notice citing violation of rule 5 concerning creation of additional accounts to bypass restrictions.

The author had never operated secondary accounts. He sent formal requests under Article 14 of 152-FZ for disclosure of personal data processing and a consumer-protection claim demanding account restoration and precise reasons for the block.

Support initially claimed an automated system had detected IP overlap with previously banned accounts. The account was restored the same day. Shortly afterward the platform changed the account type to commercial, requiring a monthly payment of 56,000 rubles for search indexing.

After additional legal correspondence the platform reversed the commercial classification on 26 August and restored normal user status. Zamirovich continues to document the case on his Telegram channel Lawyer without bugs.

Related articles

HabrFraud & Social Engineering

Email Graph Analysis Detects Impersonated Suppliers When DKIM and SPF Pass

Security researchers have outlined a practical method to identify business email compromise attempts that bypass traditional authentication checks. The approach relies solely on metadata from mail server logs to build communication profiles between external and internal addresses. By tracking first contact, one-way traffic, dormant periods, unusual sending hours, and domain similarity, analysts can flag high-risk messages requesting payment changes. The technique works against mailbox takeover scenarios where attackers reuse legitimate threads and valid signatures. Implementation uses existing Postfix or Microsoft Exchange logs and requires no new infrastructure beyond daily exports. A simplified version focusing only on lookalike domain detection can be built in a single evening and still catches most supplier impersonation attempts.

HabrFraud & Social Engineering

Developer Releases PhishIntel Open-Source Tool for Phishing Site Analysis and Risk Scoring

A developer has published PhishIntel, a lightweight Python-based OSINT application designed to analyze domains and evaluate phishing risk. The tool performs extensive checks including domain structure analysis, DNS records, RDAP and WHOIS data, TLS certificates, HTTP redirects, page content, security headers, and JavaScript static analysis. It generates structured JSON reports containing risk scores with explanatory indicators. Optional integrations with VirusTotal, Google Safe Browsing, URLhaus, Nmap, Nuclei, ZAP, and Playwright enable reputation checks, dynamic browser analysis, and active scanning. The project aims to help identify suspicious sites used in schemes such as the recent fake fuel sales campaign that defrauded victims of at least 3.7 million rubles. The author invites feedback from security professionals to improve the codebase.

AntiMalwareFraud & Social Engineering

Russian Court Bans Advertising for Renting and Selling Third-Party Bank Cards

The Chertanovsky District Court of Moscow has ruled that information promoting the rental and sale of other people's bank cards is prohibited for distribution in Russia. The decision targets a website and two Telegram channels that offered users the chance to temporarily lend or permanently sell their cards to third parties. Such schemes are commonly used to recruit drops who help receive, transfer, and cash out stolen funds. The court found that these proposals violate the rights and legitimate interests of citizens. Owners of the resources could not be identified, and domain registrars were foreign companies. VTB had previously warned about these schemes in 2024, noting that card owners risk ending up on bank blacklists, losing access to financial services, and facing criminal charges. The Ministry of Internal Affairs has also highlighted that transferring bank cards and accounts to outsiders can lead to criminal liability, with fraudsters particularly targeting children and teenagers.

HabrFraud & Social Engineering

Smart Engines Patents AI Method to Detect Holographic Security Features in Documents Using Visible Light Only

Smart Engines has developed and patented a new technique that identifies optically variable devices such as holograms on identity documents without requiring ultraviolet illumination. The approach relies on a standard document scanner equipped with six independently controlled LEDs that capture a sequence of six images under different lighting angles while the document and camera remain stationary. After dark-current correction and calibration against a white reference sheet, the system normalizes the images and computes per-pixel color-vector standard deviation to generate an OVD map. A simple thresholding and region-of-interest analysis then produces a binary verdict indicating whether a genuine holographic element is present. The method effectively distinguishes original documents from high-quality color prints, photocopies, and physical replicas that cannot reproduce the angle-dependent color shifts of real OVDs. All processing occurs with existing scanner hardware, demonstrating that algorithmic interpretation of controlled illumination can add a new authenticity signal without additional optics or spectral channels.