logo

Hackers Abuse Trusted Platforms to Steal Bank Credentials From Philippine Users

ID: 92fbc8fb-d192-5fe3-9974-123d029c8e8f

STIX ID: report--92fbc8fb-d192-5fe3-9974-123d029c8e8f

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-03

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

A coordinated phishing campaign (PHISLES) targeting Philippine online banking customers since January 2024 has distributed over 900 malicious links and confirmed more than 400 victims by using compromised real email accounts and redirect chains through trusted platforms (Google Business Profile, AMP CDN, Google Cloud Workstations, URL shorteners, Cloudflare workers/pages) and a hijacked educational domain to capture credentials and OTPs in real time and withdraw funds within minutes; the report describes the campaign’s TTPs and recommends tougher URL verification, MFA enforcement, DNS/registrar audits, and bank customer notifications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.