logo

Diesel Vortex: Exploring connections to Russian LLCs

ID: fc1fc923-2171-5244-b25e-f12296ea8390

STIX ID: report--fc1fc923-2171-5244-b25e-f12296ea8390

Feed Name: Ctrl-Alt-Int3l

Threat Score
72/100

Date Published: 2026-02-23

Date Updated: 2026-04-19

Author: Ctrl-Alt-Intel

...
...

**Executive summary:** This OSINT investigation identifies "Diesel Vortex," a financially motivated phishing-as-a-service operation (branded Global Profit / MC Profit Always) that harvested over 1,600 credentials from logistics-sector targets, documents Armenian-speaking operator coordination via Telegram logs, details phishing kit infrastructure and IOCs, and pivots on a domain RDAP email to link the infrastructure to several Russian-registered logistics and warehousing LLCs—supporting correlation between the phishing operation and entities in the same sector while explicitly noting correlation does not equal proven attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.