According to Bleeping Computer, a financially motivated threat group known as "Diesel Vortex" has been actively engaged in sophisticated phishing attacks targeting the freight and logistics sectors across the U.S. and Europe since September 2025. The group has successfully compromised numerous platforms and service providers crucial to the industry, leading to the theft of a significant number of credentials.The Diesel Vortex campaign, also marketed as "Global Profit" and "MC Profit Always," utilizes 52 domains and a highly organized operation that includes a call center and dedicated staff. Researchers discovered an exposed SQL database and Telegram logs, suggesting the actors are Armenian-speaking and linked to Russian infrastructure. The attacks employ phishing kits, Zoho SMTP, and Zeptomail, using Cyrillic homoglyphs to bypass security filters. Voice phishing and infiltration of Telegram channels are also part of their tactics. Victims are directed to pixel-level clone phishing pages that capture credentials, permit data, MC/DOT numbers, fuel card information, and two-factor authentication codes. The group has stolen 1,649 unique credentials from platforms like DAT Truckstop, TIMOCOM, and EFS.The group's activities extended beyond credential theft to include freight impersonation and cargo diversion, underscoring the need for enhanced cybersecurity measures within the supply chain. The operation has since been disrupted through a coordinated effort by multiple cybersecurity firms and platform providers, including GitLab and Cloudflare.Source: Bleeping Computer
Identity, Threat Intelligence, Phishing

Diesel Vortex phishing campaign targets freight and logistics operators

(Stock Photo, Getty Images)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



