Fraudsters hide behind a well-known brand to get to other people's cards. Cybercriminals have started using the "Yandex Delivery" brand to steal money from users of free classifieds services in Russia and Kazakhstan. This was reported by the cybersecurity company F6.
F6 recorded a new scenario of the "Mammoth" scam scheme, in which cybercriminals operate under the brand of a popular internet service. Analysts found more than 20 fake websites associated with the scheme and designed to deceive users in Russia and Kazakhstan. More than 3,000 users are registered in the groups operating under the scheme.
The scheme includes two scenarios. In the first case, a scammer, posing as a buyer, responds to an ad for a product, offers to use "Yandex Delivery," and sends a link to a fake website. The seller is offered to "receive money" before shipping the product, but to do this, they are asked to enter bank card details, and then a code from an SMS, which effectively gives the attackers access to the victim's account.
In the second scenario, the scammer acts as a seller and offers the buyer to pay for the goods upon receipt through a fake payment service, also extorting card details.
Fake websites use brand variations with typos in their domains. Resources are created through special Telegram bots.
In just one and a half years, from July 2024 to December 2025, scammers stole more than 1 billion rubles from users in Russia.

Комментарии