Fake Gov Sites Lure Central Asia Users for Cash

The Record · Medium sophistication
Last updated September 15, 2026

Researchers found a large scam campaign using hundreds of fake government and news websites in Uzbekistan, Belarus, and Tajikistan. The sites lure people with promises of government-backed cash payments or passive income, then collect phone numbers and other personal data for follow-up calls/emails. Victims are pushed to pay “fees,” share documents, or install a malicious mobile app that can give attackers control of the device.

How the attack worked

Researchers at F6 uncovered a large scam operation using more than 360 fraudulent domains built to imitate official government and regional news websites across Uzbekistan, Belarus, and Tajikistan. The sites lure visitors with promises of government financial assistance or passive income through supposed government-backed programs. Victims are initially asked for minimal information, typically just a name and phone number, to check eligibility for a payout.

Once that data is submitted, scammers escalate the contact by phone or email, often posing as a personal manager assigned to the victim's case. From there, the campaign follows a familiar social engineering escalation: requests for a commission or processing fee to release the funds, collection of additional personal information including passport scans, and in some cases instructions to install a mobile application supposedly required for identity verification. That application is actually malware capable of giving attackers control over the device.

Why it succeeded

The campaign leans heavily on trust in government institutions and, in more sophisticated cases, trust in familiar news sources. Some fake sites go beyond a simple landing page and mimic regional news outlets, publishing fabricated stories about government assistance programs before funneling readers into a questionnaire. This added layer of legitimacy makes the eventual request for personal details feel like a natural next step rather than a red flag.

The low initial ask (just a name and phone number) also lowers resistance. Once someone has taken that first small step, they are more likely to continue engaging with follow-up calls, fee requests, and document submissions.

What to watch for

  • Unsolicited claims of eligibility for a government payout or passive income program
  • A phone or email follow-up from a self-described "personal manager" after submitting contact details
  • Any request to pay a commission or processing fee to receive promised money
  • Requests to submit passport scans or other identity documents as part of "verification"
  • Instructions to install a mobile app to register for or verify a benefit program

How to build resistance

Organizations should remind employees and customer-facing teams that legitimate government programs do not require upfront fees to release funds, and that unexpected payout offers should be verified through official government channels rather than links in an email or website. Any request to install an unfamiliar app tied to a financial benefit should be treated as a likely malware attempt and escalated to IT or security. Because the campaign specifically uses fake news content to build credibility, awareness training should also cover how to distinguish legitimate news sources from lookalike sites pushing readers toward personal data forms.

Key findings

  • F6 identified “more than 360 fraudulent domains” used to imitate government and news websites in Uzbekistan, Belarus, and Tajikistan.
  • The lure is fake eligibility for government financial assistance or passive income via “government-backed programs.”
  • Victims are first asked for minimal data (e.g., name and phone number), then contacted by scammers “through phone or email.”
  • Follow-up social engineering includes requesting a “commission or processing fee,” collecting more personal information (including passport scans), and directing victims to install a “mobile application” that is actually malware.
  • Some fake sites mimic regional news outlets and publish fake stories to build credibility before sending users to questionnaires.

Who’s being targeted

  • Commonly targeted roles: All employees, HR (employee assistance inquiries), Finance (fraud awareness), Customer-facing teams/call centers, Executives (scam risk awareness).
  • Affected industries: General public/consumers, Government services (impersonated), Media/news (impersonated).
  • Attack channels: website, vishing.
  • Impersonated: Government social program / 'personal manager' for a government-backed payout, Regional news website (publishing a story about government assistance), Government program registration/identity verification service.

Red flags to watch for

  • Promises of easy money from a government program ("weekly payments")
  • Request for a fee/commission to receive the payout
  • Unsolicited caller posing as a "personal manager" after you submit details
  • A news-looking page that quickly pushes you into a form/questionnaire
  • Government-benefit story that cannot be verified on official channels
  • Unnecessary collection of personal contact information
  • Being told to install an app from an untrusted source for a payout/benefit
  • App requirement appears after you submit contact details
  • Pressure to complete “verification” to receive money
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How many fake domains were found in this campaign?

Researchers at F6 identified more than 360 fraudulent domains imitating government and news websites in Uzbekistan, Belarus, and Tajikistan.

What do the fake sites promise victims?

They promise eligibility for government financial assistance or passive income through supposed government-backed programs, asking initially for just a name and phone number.

What happens after someone submits their information?

Scammers follow up by phone or email, often posing as a personal manager, and may ask for a commission or processing fee, additional personal details like passport scans, or installation of a mobile app that is actually malware.

How can employees or the public protect themselves?

Treat unsolicited government payout offers as suspicious, verify claims through official government channels, never pay a fee to receive a promised payment, and avoid installing 'verification' apps tied to such offers.

Read the video transcript

Imagine a website that looks like an official Uzbekistan or Belarus government portal, telling you you’re eligible for weekly cash payments. Researchers found more than 360 of these fake government and news sites across Uzbekistan, Belarus, and Tajikistan. First they ask for just your name and phone number, then a 'personal manager' calls to help you claim the money. On the call, they push you to pay a 'commission fee,' send passport scans, or install a mobile app that secretly gives them control of your device, this all started from that one fake news or government page. If you see a site promising government-backed weekly payouts, stop. Don’t click through, go to the official government portal you already know, or call our security team to check it first.

Similar attacks

Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026