Identity, Threat Intelligence, Phishing

Diesel Vortex phishing campaign targets freight and logistics operators

Today’s columnist, Yochai Corem of Cyberint, writes that companies have to accept that they will face a supply chain attack. (Stock Photo, Getty Images)

According to Bleeping Computer, a financially motivated threat group known as "Diesel Vortex" has been actively engaged in sophisticated phishing attacks targeting the freight and logistics sectors across the U.S. and Europe since September 2025. The group has successfully compromised numerous platforms and service providers crucial to the industry, leading to the theft of a significant number of credentials.

The Diesel Vortex campaign, also marketed as "Global Profit" and "MC Profit Always," utilizes 52 domains and a highly organized operation that includes a call center and dedicated staff. Researchers discovered an exposed SQL database and Telegram logs, suggesting the actors are Armenian-speaking and linked to Russian infrastructure. The attacks employ phishing kits, Zoho SMTP, and Zeptomail, using Cyrillic homoglyphs to bypass security filters. Voice phishing and infiltration of Telegram channels are also part of their tactics. Victims are directed to pixel-level clone phishing pages that capture credentials, permit data, MC/DOT numbers, fuel card information, and two-factor authentication codes. The group has stolen 1,649 unique credentials from platforms like DAT Truckstop, TIMOCOM, and EFS.

The group's activities extended beyond credential theft to include freight impersonation and cargo diversion, underscoring the need for enhanced cybersecurity measures within the supply chain. The operation has since been disrupted through a coordinated effort by multiple cybersecurity firms and platform providers, including GitLab and Cloudflare.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds