haveibeensquatted.com Diesel Vortex: Russian Cybercrime Group Targets US and EU Freight Companies
Article Content
- •Diesel Vortex targeted US and EU logistics firms, stealing over 1,600 credentials.
- •The group used phishing-as-a-service tactics, including impersonation and double-brokering.
- •Collaboration among cybersecurity firms led to the exposure and takedown of the group's infrastructure.
In February 2026, the cybercrime group Diesel Vortex was uncovered, targeting freight and logistics companies in the US and EU. The group employed phishing-as-a-service tactics, harvesting over 1,600 unique login credentials from major logistics platforms. Their operations included impersonation of legitimate carriers and brokers, utilizing sophisticated spearphishing and voice phishing techniques. Internal logs revealed coordination among Armenian-speaking operators, indicating a complex network behind the attacks. The group also engaged in double-brokering, redirecting freight under stolen identities. Investigators from Have I Been Squatted and Ctrl-Alt-Intel collaborated to analyze the group's infrastructure, leading to the exposure of their codebase and operational plans. The operation is assessed to have been active from September 2025 to February 2026, with ongoing investigations into earlier activities. The takedown of their infrastructure involved multiple cybersecurity firms and organizations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Central Dispatch in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Corp MDM Spyware Targets Logistics Sector via Fake Google Play Pages A malware campaign has emerged targeting the logistics sector, distributing Android spyware named Corp MDM through counterfeit Google Play pages branded as CEVA and TKW Logistics. The malicious APK, disguised as a system service, is designed to exfiltrate SMS content, divert calls, and operate a hidden service. The…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…