In short: Russian cybersecurity firm F6 has warned that fraudsters are pivoting to hijacking existing .ru, .рф, and .su websites after Russia's mandatory domain administrator identification requirement (via ESIA/Gosuslugi) eliminated the anonymous-registration loophole. F6's warning, published on September 1, 2026 by RIA Novosti, follows the August 28 blocking of "nulltrace" — a service that helped fraudsters bypass the new ID rules. Site owners and users of Russian web resources should act now.
What changed: mandatory identity checks for .ru domains
Until 2026, registering a .ru domain was relatively anonymous — minimal identity verification made it easy for fraudsters to spin up phishing sites, get blocked by regulators, and quickly register new lookalike domains. That playbook is now closed.
Russia's new requirement forces all domain administrators to verify their identity through ESIA — the Unified Identification and Authentication System, widely known as Gosuslugi (the government services portal). Registration now requires a real, verified identity tied to a Russian national ID. No more throwaway domains.
Complementing this rule change, F6 worked with regulators to block nulltrace on August 28, 2026. Active since March 5, 2026, nulltrace had offered a workaround that let fraudsters register .ru domains without proper identification. Its removal, reported by Vedomosti and Xakep.ru, closed a secondary evasion route.
How fraudsters adapted: the site-hijacking wave
Blocked from registering new anonymous domains, attackers made a logical pivot: target existing legitimate sites. A domain with an established history is far more trusted by users, browsers, and search engines than a freshly registered one — which makes hijacked sites a particularly effective attack vector.
The typical attack chain:
- Target scanning. Attackers scan .ru domains running outdated CMS software — unpatched WordPress, Bitrix, obsolete plugins — or with weak admin credentials.
- Compromise. Exploiting known vulnerabilities or brute-forcing passwords, they gain control of the site's admin panel.
- Content replacement. On the trusted domain, attackers plant phishing pages, malware download links, or redirect scripts — often triggered only for certain user segments to evade detection by the legitimate site owner.
- Monetization. The hijacked site harvests credentials, distributes malware, or is rented out to other threat actors.
F6's warning, issued to RIA Novosti on September 1, 2026, noted a measurable rise in this attack pattern and urged .ru site owners to take urgent protective measures.
What this means for everyday users
You don't need to own a site to be at risk — being a visitor is enough. Imagine a forum, online shop, or blog you have trusted for years in the .ru zone. The domain is the same, the HTTPS padlock is present, the design looks familiar. But the content is now malicious.
Realistic scenarios:
- Phishing. A familiar login or payment form now sends your credentials directly to attackers rather than the legitimate service.
- Drive-by downloads. Hidden scripts exploit browser or plugin vulnerabilities the moment the page loads, attempting to install malware silently.
- Redirect campaigns. The compromised site sends you to a malicious page, or your browser starts warning about it where it never did before.
An important distinction: a VPN cannot fix a compromised server. A VPN encrypts the network tunnel between your device and the internet — this defends against eavesdropping at the connection layer. If the web server itself is under attacker control, a VPN will deliver the malicious content to you just as reliably as it would deliver legitimate content. Against hijacked sites, your effective defenses are an updated browser, antivirus software with web protection, and your own vigilance.
That said, LiMP VPN defends against closely related threats: it prevents your ISP or a network-level attacker from spoofing DNS responses (redirecting you to a fake site instead of the real one), intercepting unencrypted connections, or tracking your browsing history. These are complementary layers — each addresses a different part of the threat model.
How to protect yourself
For users:
- Check the SSL certificate. Click the padlock in the address bar and verify the certificate is issued for the correct domain and hasn't expired. An unexpected or missing certificate is a hard stop — enter no data.
- Trust browser security warnings. Chrome, Firefox, and Safari maintain up-to-date threat databases and warn before loading known-malicious pages. Keep your browser updated so those lists stay current.
- Use antivirus with web protection. Modern endpoint solutions can detect malicious scripts and drive-by payloads at the page-load stage, before they execute.
- Be suspicious of unexpected design changes. If a login or payment form looks different from what you remember, close the page and contact the service directly before entering any credentials.
For .ru site owners: update your CMS, plugins, and themes immediately — unpatched software is the primary entry vector; enable two-factor authentication on your admin panel; set up file integrity monitoring to detect unauthorized changes; and keep regular backups in an off-site location.
For network-level protection, LiMP VPN encrypts your connection and shields your browsing from your ISP and public network operators. Our zero-logs policy means no record of your visits is ever stored. It is a necessary layer in a defense-in-depth setup — complementing, not replacing, careful browsing habits.
