Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years.

According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The operation has been ongoing since 2017.

"Most of the content on these fraudulent websites was copied from the legitimate company websites. Some also used lookalike domain names," the cybersecurity company said in an exclusive report shared with The Hacker News. "These fake websites, available in English, French, Arabic, and Russian, were used to target international customers and steal advance payments for goods that did not exist."

Analysis indicates that the phony prepayment scheme has primarily singled out organizations across the Commonwealth of Independent States (CIS) countries with a specific focus on the business-to-business (B2B) sector and international trade via cold calls, phishing email campaigns, and fraudulent corporate websites to initiate contact with potential customers and distribute business documents containing the banking details of fake "subsidiary" companies.