While most phishing campaigns aim to steal financial data or distribute malware, a coordinated operation now targeting Russians carries stakes of an entirely different magnitude. Those who fall victim to certain phishing schemes—specifically ones impersonating Ukrainian paramilitary organizations fighting against the Kremlin—risk losing their freedom or their lives.

Researchers at Silent Push, a security firm, have identified a network spanning several dozen phishing domains designed to mimic the recruitment portals of Ukrainian paramilitary units and Ukrainian government intelligence agencies. One such domain, legiohliberty[.]army, replicates the legitimate homepage of the Freedom of Russia Legion (also known as "Free Russia Legion"), a Ukraine-based paramilitary unit founded three years ago and composed of Russian nationals opposed to Vladimir Putin's invasion.

The fraudulent site closely mirrors the authentic domain legionliberty[.]army and hosts an interactive Google Form requesting visitors to disclose their name, gender, age, email address or Telegram handle, country, citizenship, military background, political beliefs, reasons for joining, and personal habits. Silent Push stated in a report released today: "Participation in such anti-war actions is considered illegal in the Russian Federation, and participating citizens are regularly charged and arrested." The firm added: "All observed campaigns had similar traits and shared a common objective: collecting personal information from site-visiting victims. Our team believes it is likely that this campaign is the work of either Russian Intelligence Services or a threat actor with similarly aligned motives."

Zach Edwards, a researcher at Silent Push, identified multiple overlaps between the fake Legion Liberty site and rusvolcorps[.]net, another phishing domain that impersonates the recruitment page of the Russian Volunteer Corps (rusvolcorps[.]com), a Ukrainian far-right paramilitary group. This fraudulent site similarly employs a Google Forms interface to harvest applicant information.

The phishing infrastructure extends further. Additional domains connected to the campaign include ciagov[.]icu, which duplicates content from the official U.S. Central Intelligence Agency website, and hochuzhitlife[.]com, which replicates the Ministry of Defense of Ukraine and General Directorate of Intelligence (the legitimate domain being hochuzhit[.]com).

Search Engine Manipulation

According to Edwards, these phishing sites do not appear to be distributed through email campaigns. Instead, evidence suggests the perpetrators are leveraging search engine optimization techniques to position the fraudulent sites prominently in search results for queries related to these anti-Putin organizations.

In August 2024, security researcher Artem Tamoian documented a striking disparity in search results. When searching for "Freedom of Russia legion" on Yandex, Russia's dominant domestic search engine, the top result was a phishing page, whereas Google.com returned the legitimate website as its first result. Tamoian observed: "I think at least some of them are surely promoted via search. My first thread on that accuses Yandex, but apart from Yandex those websites are consistently ranked above legitimate in DuckDuckGo and Bing. Initially, I didn't realize the scale of it. They keep appearing to this day."

Tamoian, a Russian native who departed the country in 2019, founded malfors.com, a cyber investigation platform. He subsequently identified two additional impersonation sites—legionliberty[.]world and rusvolcorps[.]ru—and reported them to Cloudflare. When Cloudflare implemented phishing warnings to block these domains, the underlying infrastructure was revealed to belong to Stark Industries Solutions Ltd., a known "bulletproof hosting" provider.

Bulletproof Hosting and Russian Intelligence

Stark Industries Solutions emerged just two weeks before Russia's February 2022 invasion of Ukraine, suddenly controlling hundreds of thousands of Internet addresses, many originally allocated to Russian government entities. KrebsOnSecurity published an extensive investigation of Stark in May 2024, documenting its repeated use as infrastructure for distributed denial-of-service attacks, phishing operations, malware distribution, and disinformation campaigns attributed to Russian intelligence agencies and pro-Kremlin hacking groups.

The consequences for those ensnared are severe. In March 2023, Russia's Supreme Court classified the Freedom of Russia Legion as a terrorist organization, meaning Russians caught maintaining contact with the group face sentences ranging from 10 to 20 years imprisonment.

Search results showing news articles about people in Russia being sentenced to lengthy prison terms for attempting to aid Ukrainian paramilitary groups.

A Trap for the Vulnerable

Tamoian explained his motivation for investigating these phishing operations: "I started looking into those phishing websites, because I kept stumbling upon news that someone gets arrested for trying to join [the] Ukrainian Army or for trying to help them. I have also seen reports [of] FSB contacting people impersonating Ukrainian officers, as well as using fake Telegram bots, so I thought fake websites might be an option as well."

Reports regularly emerge from Russia documenting arrests of individuals charged with attempting to carry out actions directed by a "Ukrainian recruiter." Courts consistently impose severe penalties regardless of the defendant's age. Tamoian noted: "This keeps happening regularly, but usually there are no details about how exactly the person gets caught. All cases related to state treason [and] terrorism are classified, so there are barely any details."

While Tamoian lacks direct evidence connecting specific arrests and convictions to these phishing sites, he remains convinced they represent part of a broader Russian government operation. He stated: "Considering that they keep them alive and keep spawning more, I assume it might be an efficient thing. They are on top of DuckDuckGo and Yandex, so it unfortunately works."

Source: Krebs on Security