{"id":101212,"date":"2026-02-24T19:13:43","date_gmt":"2026-02-24T22:13:43","guid":{"rendered":"https:\/\/shipping.einnews.com\/article\/895214769"},"modified":"2026-02-24T19:13:43","modified_gmt":"2026-02-24T22:13:43","slug":"phishing-operation-with-links-to-russia-armenia-compromised-western-cargo-companies-researchers-find","status":"publish","type":"post","link":"https:\/\/new7.shop\/zerocostfreehost\/index.php\/2026\/02\/24\/phishing-operation-with-links-to-russia-armenia-compromised-western-cargo-companies-researchers-find\/","title":{"rendered":"Phishing operation with links to Russia, Armenia compromised Western cargo companies, researchers find"},"content":{"rendered":"<div><img data-opt-id=758893364  fetchpriority=\"high\" decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAIAAAAAAAP\/\/\/ywAAAAAAQABAAACAUwAOw==\" fifu-lazy=\"1\" fifu-data-sizes=\"auto\" fifu-data-srcset=\"https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=75&resize=75&ssl=1 75w, https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=100&resize=100&ssl=1 100w, https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=150&resize=150&ssl=1 150w, https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=240&resize=240&ssl=1 240w, https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=320&resize=320&ssl=1 320w, https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=500&resize=500&ssl=1 500w, https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=640&resize=640&ssl=1 640w, https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=800&resize=800&ssl=1 800w, https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=1024&resize=1024&ssl=1 1024w, https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=1280&resize=1280&ssl=1 1280w, https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1&w=1600&resize=1600&ssl=1 1600w\" fifu-data-src=\"https:\/\/mlmjbqro95r8.i.optimole.com\/cb:bOxR.6a5\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/i0.wp.com\/cms.therecord.media\/uploads\/format_webp\/shipping_cargo_f62882ef10.jpg?ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<div id>\n<p class=\"paragraph\"> Researchers have uncovered and taken down the infrastructure of a phishing operation run by Russian cybercriminals targeting freight companies in the U.S. and Europe.&nbsp; <\/p>\n<p class=\"paragraph\"> Over a five-month period, the group, dubbed Diesel Vortex, stole more than 1,600 login credentials from accounts at logistics platforms, which allowed thieves to intercept and divert freight shipments and commit check fraud.&nbsp; <\/p>\n<p class=\"paragraph\"> The researchers with the domain protection platform Have I Been Squatted <a href=\"https:\/\/haveibeensquatted.com\/blog\/diesel-vortex-inside-the-russian-cybercrime-group-targeting-us-eu-freight\" target=\"_blank\" rel=\"noopener noreferrer\">discovered<\/a> an exposed .git directory, which revealed the ins and outs of the operation, including messages sent between the cybercriminals.&nbsp; <\/p>\n<p class=\"paragraph\"> The leaked repository exposed a phishing-as-a-service platform that was in the works to be marketed to customers as \u201cMC Profit Always,\u201d a likely reference to \u201cmotor carriers.\u201d&nbsp; <\/p>\n<p class=\"paragraph\"> The Diesel Vortex cybercriminals built phishing infrastructure targeting users of the platforms that power the freight and logistics industries, like load boards \u2014 marketplaces where shippers, brokers and carriers connect \u2014 fleet management portals and fuel card systems.&nbsp; <\/p>\n<p class=\"paragraph\"> They impersonated carriers and brokers and were able to access freight systems. Messages seem to show them engaged in \u201cdouble-brokering,\u201d when loads are booked with a stolen carrier identity before the freight is reassigned to a different carrier.&nbsp; <\/p>\n<p class=\"paragraph\"> The researchers were able to find the outfit\u2019s organizational map, revealing a sophisticated operation including a call center, mail support and employees responsible for connecting with drivers and other logistics contacts. <\/p>\n<p class=\"paragraph\"> \u201cThis blueprint only reinforced what the codebase had already made clear: this was not an opportunistic campaign. It was a deliberate, structured criminal enterprise with defined roles, revenue targets, and a long-term growth strategy,\u201d Have I Been Squatted researchers wrote.&nbsp; <\/p>\n<p class=\"paragraph\"> The company worked in collaboration with the cyber threat research outfit <a href=\"https:\/\/haveibeensquatted.com\/blog\/diesel-vortex-inside-the-russian-cybercrime-group-targeting-us-eu-freight\" target=\"_blank\" rel=\"noopener noreferrer\">Ctrl-Alt-Int3l<\/a>, which discovered in the phishing panel source code mention of a domain registered through a Russian provider and linked to a Russian-registered email address. <\/p>\n<p class=\"paragraph\"> That email was then linked through corporate records to several Russian companies working in warehousing, transportation and wholesale trade. Recorded Future News reached out to the email address for comment and as of press time had not received a reply.&nbsp;&nbsp; <\/p>\n<p class=\"paragraph\"> Along with clear links to Russia, Armenian-speaking operators were also involved in the operation, with one of the criminals telling another he was located in Yerevan. In one chat, a member of the group asks in Armenian if they have the credentials of a carrier with \u201c250k cargo\u201d \u2014 in other words, one insured to carry high-value freight.&nbsp; <\/p>\n<p class=\"paragraph\"> According to the researchers, Google Threat Intelligence Group, Cloudflare, GitLab, IPInfo and Ping Identity were involved in taking down the infrastructure.&nbsp; <\/p>\n<p class=\"paragraph\"> Cargo theft has exploded in recent years, driven by the increasingly digital nature of the business, with annual losses estimated to be around $35 billion. In November, researchers at Proofpoint documented <a href=\"https:\/\/therecord.media\/cargo-theft-hackers-remote-monitoring-tools\" target=\"_blank\" rel=\"noopener noreferrer\">a hacking campaign<\/a> with links to organized crime targeting trucking and logistics companies with remote monitoring tools.&nbsp;&nbsp; <\/p>\n<p class=\"paragraph\"> Last month, the House Judiciary Committee advanced the \u201c<a href=\"https:\/\/www.cbo.gov\/publication\/62176\" target=\"_blank\" rel=\"noopener noreferrer\">Combatting Organized Retail Crime Act of 2025<\/a>,\u201d a bill to establish a coordinated federal response to cargo theft. It would also create new criminal penalties for the laundering of illicit proceeds or the sale of stolen goods. <\/p>\n<\/div>\n<div>\n<div class=\"mb-4\">Get more insights with the <\/p>\n<p>Recorded Future<\/p>\n<p>Intelligence Cloud.<\/p>\n<\/div>\n<p><a class=\"underline\" target=\"_blank\" rel=\"noopener noreferrer\" href=\"https:\/\/www.recordedfuture.com\/platform?mtm_campaign=ad-unit-record\">Learn more.<\/a><\/div>\n<p><strong><a href=\"https:\/\/blockads.fivefilters.org\"> <\/a><\/strong> <a href=\"https:\/\/blockads.fivefilters.org\/acceptable.html\"> <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8230; to intercept and divert <span class=\"match\">freight<\/span> shipments and commit check &#8230; the platforms that power the <span class=\"match\">freight<\/span> and logistics industries, like &#8230; carrier identity before the <span class=\"match\">freight<\/span> is reassigned to a &#8230; 250k <span class=\"match\">cargo<\/span>\u00e2\u0080\u009d \u00e2\u0080\u0094 in other words, one insured to carry high-value <span class=\"match\">freight<\/span> &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-101212","post","type-post","status-publish","format-standard","hentry","category-news","wpcat-1-id"],"_links":{"self":[{"href":"https:\/\/new7.shop\/zerocostfreehost\/index.php\/wp-json\/wp\/v2\/posts\/101212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new7.shop\/zerocostfreehost\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new7.shop\/zerocostfreehost\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new7.shop\/zerocostfreehost\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/new7.shop\/zerocostfreehost\/index.php\/wp-json\/wp\/v2\/comments?post=101212"}],"version-history":[{"count":0,"href":"https:\/\/new7.shop\/zerocostfreehost\/index.php\/wp-json\/wp\/v2\/posts\/101212\/revisions"}],"wp:attachment":[{"href":"https:\/\/new7.shop\/zerocostfreehost\/index.php\/wp-json\/wp\/v2\/media?parent=101212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new7.shop\/zerocostfreehost\/index.php\/wp-json\/wp\/v2\/categories?post=101212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new7.shop\/zerocostfreehost\/index.php\/wp-json\/wp\/v2\/tags?post=101212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}