Threats Tagged 'sanctions evasion'
View all threats tagged with 'sanctions evasion'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'sanctions evasion'
Click on any threat for detailed analysis and mitigation recommendations
Iranian and Russian shadow fleet vessels are utilizing sophisticated online infrastructure consisting of over 36 inauthentic websites to facilitate sanctions evasion. These websites impersonate ship registries, national maritime administrations, seafarer training organizations, protection and indemnity clubs, and classification societies from jurisdictions including Comoros, Benin, Bhutan, Cameroon, Chad, Equatorial Guinea, Gambia, Haiti, Malawi, Nicaragua, and Zambia. The infrastructure operates through three identified clusters designated Alpha, Bravo, and Charlie, which demonstrate technical overlaps suggesting a broader ecosystem supporting multiple sanctions evasion networks. Operators employ tactics including automated document generation, typosquatting, identity spoofing, and mutual endorsement loops between fraudulent entities. Attribution includes links to Indian web development company Oceaniek Technologies and two Syrian nationals. The infrastructure has documented connections to seventeen vesse... Join the discussion | AlienVault OTX General | 06/11/2026, 16:08:08 UTC Added: 06/15/2026, 19:45:18 UTC |
Investigation of DPRK-linked fake IT worker infrastructure began after cryptocurrency researcher ZachXBT identified domain luckyguys[.]site connected to illicit payments. Analysis of 30 days of network activity associated with IP 163.245.219[.]19 revealed concentrated VPN usage patterns, with Astrill VPN (37.5%), Mullvad (32.25%), and Proton VPN (6.25%) being prominent. American and Latvian residential IPs communicated with the infrastructure, showing frequent Astrill VPN usage and connectivity to Gmail, ChatGPT, and Workana freelance platform. A second IP, 216.158.225[.]144, was discovered through X509 certificate analysis. Traffic dropped sharply following public exposure, consistent with adversary behavior of abandoning attributed infrastructure. The activity suggests a distributed network of remote IT workers participating in sanctions evasion workflows, leveraging AI tools and freelance platforms to obtain employment under false identities. Join the discussion | AlienVault OTX General | 04/23/2026, 03:27:33 UTC Added: 04/23/2026, 09:06:03 UTC |
Showing 1 to 2 of 2 results