Iranian and Russian shadow fleet networks are using more than 36 inauthentic websites to impersonate maritime administrations, ship registries, classification societies, and seafarer certification bodies in order to generate fraudulent documents and evade sanctions. The infrastructure spans three linked clusters and is associated with vessels and organizations including Benin, the Comoros, Oceaniek Technologies, Med Lloyd Classification Society, Hellas Naval Bureau of Shipping, and Pioneers Maritime Ship Management. #BeninMaritimeAdministration #OceaniekTechnologies #MedLloydClassificationSociety #HellasNavalBureauofShipping #PioneersMaritimeShipManagement #Marinegov
Keypoints
- Insikt Group identified over 36 inauthentic websites used by Iranian and Russian shadow fleet-related sanctions evasion networks.
- The websites impersonate ship registries, maritime administrations, training organizations, P&I clubs, and classification societies to create credibility.
- Three clusters of activity, labeled Alpha, Bravo, and Charlie, share infrastructure, domain patterns, and operational security mistakes.
- Cluster Alpha includes a PDF certificate generator that creates fraudulent seafarer documents and QR codes for inspections.
- Cluster Bravo is linked to fraudulent maritime organizations such as Med Lloyd Classification Society, Hellas Naval Bureau of Shipping, and seafarer training sites.
- Cluster Charlie uses a layered validation scheme where fake maritime administrations endorse other fake entities to reinforce legitimacy.
- The infrastructure is tied to sanctioned or suspicious vessels linked to Russian and Iranian shadow fleet activity, with indications of links to multiple front companies and service providers.
MITRE Techniques
- [T1583.001 ] Acquire Infrastructure: Domains â Threat actors registered and used multiple fake maritime domains to support sanctions evasion and impersonation (âover 36 inauthentic websitesâ; âdomain registration patternsâ).
- [T1583.006 ] Acquire Infrastructure: Web Services â The infrastructure was hosted across web services and IP ranges to support reusable fake organizations (âdifferent hosting arrangementsâ; âco-hosted on 159.198.36.123â).
- [T1036.005 ] Masquerading: Match Legitimate Resource Name or Location â Websites impersonated real maritime administrations, registries, classification societies, and training bodies (âimpersonating the Benin Maritime Administrationâ; âmasquerading as a classification societyâ).
- [T1036.003 ] Masquerading: Rename System Utilities or Files â Fraudulent websites reused legitimate-looking names and document templates to appear official (âreusing document templatesâ; âclaimed to be associated with multiple jurisdictionsâ).
- [T1001.001 ] Data Obfuscation: Junk Data â QR codes and layered website structures were used to complicate verification and enforcement (âQR codes very likely facilitate the presentation and verification of documentsâ).
- [T1056.004 ] Input Capture: Credential API Hooking â The article does not describe credential capture, but it does mention login panels and queryable databases that could support credential harvesting (âlogin pagesâ; âqueryable database of certificatesâ).
- [T1132.001 ] Data Encoding: Standard Encoding â QR codes were generated to encode links to fraudulent PDF documents (âThe app also generates QR codes linking to the PDF filesâ).
- [T1568.002 ] Dynamic Resolution: Domain Generation Algorithms â Not explicitly stated, but the reuse of multiple domain variants and subdomains suggests dynamic-style infrastructure management (âbeninmaritime[.]orgâ, âbeninmaritime[.]coâ, âbeninmaritime[.]netâ).
Indicators of Compromise
- [Domains] Fake maritime administrations, registries, and certification sites â beninmaritime[.]org, medlloyd[.]online, hellasnaval[.]net, and other domains listed in the report.
- [IP Addresses] Shared hosting and infrastructure â 159[.]198[.]36[.]123, 217[.]76[.]51[.]133, and 151[.]80[.]4[.]227.
- [Domains] Cluster Alpha and Bravo-related sites â epnicaragua[.]org, atlasregister[.]net, nauticacentro[.]mx, and isithin[.]com.
- [Domains] Cluster Charlie and related validation network â pioneersmaritime[.]com, alliance-scs[.]org, sasmaa[.]club, and zambmaritime[.]org.
- [File names] Evidence files and screenshots in open directories â tavian 1 windward.JPG, plus PDF seafarer certificates and certificate templates.
- [Organizations] Impersonated or referenced entities â Benin Maritime Administration, Oceaniek Technologies, Med Lloyd Classification Society, Hellas Naval Bureau of Shipping, and International Marine Services.
Read more: https://www.recordedfuture.com/research/cyber-maritime-sanctions-evasion