In short: The shadow service nulltrace let cybercriminals register .ru and .su domains without providing any name, phone number, or email — payments were in cryptocurrency. The platform was used to build phishing sites impersonating banks and payment systems. F6 initiated a takedown in March 2026 and published a full account of the operation in August 2026.
What Nulltrace Was and How It Operated
Nulltrace was a shadow domain registrar operating through nulltrace[.]su. Its defining feature: registering a domain in Russian zones required no personal data whatsoever — no name, no phone number, no email address. Payments were accepted exclusively in cryptocurrency. This made the service nearly invisible to standard registrar verification procedures and regulators.
According to F6, the service was actively promoted on Russian-language darknet forums. F6 analysts discovered it while investigating a phishing campaign: analysis of the email address info@nulltrace.su revealed an entire network of fake banking websites registered through the platform.
Scale of the Threat: Phishing in the .ru Zone
The .ru domain zone carries high implicit trust among Russian internet users — making it a powerful tool for fraudsters. According to F6 analytics, in 2025 the .ru zone accounted for 42.3% of all phishing domains targeting Russian users (down from 72.9% in 2024, a reduction attributed to active work by regulators and CERTs).
Typical schemes nulltrace enabled: phishing pages impersonating banks and payment systems, fake marketplace and delivery websites, and resources for financial fraud. Anonymous registration allowed operators to burn domains after each block and spin up new ones without a paper trail.
How F6 Traced and Blocked the Service
The investigation began with a phishing resource in the .su zone targeting customers of foreign banks. F6 analysts traced the associated email address and found that nulltrace had been used to register an entire network of fraudulent websites.
On 25 February 2026, F6's CERT initiated a verification procedure through the official registrar channel. The nulltrace operator failed to provide valid registration data — on 5 March 2026, the main nulltrace[.]su domain was de-delegated. All client sites in .ru and .su zones registered through the service simultaneously went offline.
Following the takedown, the nulltrace operator relocated to the .ws zone and switched providers, removing Russian-zone domains from their offering. F6 assessed that this significantly raises the cost of attacks for certain threat actors, making some fraud schemes economically unviable.
What This Means for User Protection
The nulltrace takedown demonstrates effective cooperation between a commercial cybersecurity firm and regulatory infrastructure. But the lesson for users is clear: removing one rogue registrar does not eliminate phishing — attackers adapt and migrate their infrastructure to other zones.
The core danger of phishing sites is that they look legitimate: correct logos, lookalike addresses (for example, tinkoff-pay[.]ru instead of tinkoff.ru), valid SSL certificates. Protection works on several layers:
- Check the URL carefully. Before entering a password or card details, verify the address bar character by character.
- Enable two-factor authentication. Even if credentials are stolen, a second factor protects the account.
- Encrypt your traffic. A VPN encrypts your connection and hides your requests from interception on unsecured networks — learn more on the LiMP VPN features page.
- Check for breaches. If your email has appeared in prior leaks, it may be used for targeted phishing — check at HaveIBeenPwned.
More on protecting your personal data online — in the LiMP VPN blog.
