Diesel Vortex Russian Cybercrime Group Targets Global Logistics Sector and Steals 1,600+ Credentials
A cybercrime group identified as Diesel Vortex, linked to Russia, has conducted a significant phishing campaign targeting freight and trucking companies in the United States and Europe.
A cybercrime group identified as Diesel Vortex, linked to Russia, has conducted a significant phishing campaign targeting freight and trucking companies in the United States and Europe.
The operation spanned from September 2025 to February 2026, resulting in the theft of over 1,649 login credentials from major logistics platforms, including DAT Truckstop, Penske Logistics, Electronic Funds Source (EFS), and Timocom.
The group functioned as an organized criminal service, potentially offering phishing access to other entities under the brand name "MC Profit Always." Their approach involved spearphishing emails and voice phishing calls aimed at trucking professionals, often infiltrating freight-focused Telegram groups.
By mimicking the platforms used by their targets, Diesel Vortex intercepted login credentials and multi-factor authentication codes in real time. This access facilitated shipment redirection, fund theft, and check fraud.
The campaign was uncovered by analysts at Have I Been Squatted through the detection of typosquatted domains associated with a client. An investigation revealed an exposed Git directory on a phishing server, containing the group's source code, victim database, internal communications, and future plans.
By mimicking the platforms used by their targets, Diesel Vortex intercepted login credentials and multi-factor authentication codes in real time.
A SQL dump from February 4, 2026, showed 52 phishing domains were used, targeting 75,840 contact emails, with 35 instances of EFS check fraud. The compromised data included shipment invoices and financial information, enabling invoice fraud and double-brokering.
The operation, internally named "GlobalProfit," was being developed into a Phishing-as-a-Service (PhaaS) product for Russian-speaking criminal buyers, with cryptocurrency payment options.
The group employed a sophisticated method of concealing phishing pages from both victims and security tools. Victims received links to an "advertise domain," which secretly loaded a hidden "system domain" via an invisible browser frame.
This technique bypassed most browser security warnings by displaying a legitimate-looking domain in the address bar while phishing content loaded within the frame.
To mitigate such threats, security teams are advised to employ FIDO2 hardware keys or device-bound passkeys, as these attacks can defeat standard one-time passwords and SMS codes. Additionally, DNS filtering and monitoring for typosquatted domains are critical defensive strategies.
Based on reporting by Cyber Security News.
